10

CVE-2004-1008

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
PuTTYPuTTY Version0.48
PuTTYPuTTY Version0.49
PuTTYPuTTY Version0.50
PuTTYPuTTY Version0.51
PuTTYPuTTY Version0.52
PuTTYPuTTY Version0.53
PuTTYPuTTY Version0.53b
PuTTYPuTTY Version0.54
PuTTYPuTTY Version0.55
TortoisecvsTortoisecvs Version1.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 21.63% 0.952
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C