6.8

CVE-2013-4852

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WinSCPWinSCP Version <= 5.1.5
WinSCPWinSCP Version3.7.6
WinSCPWinSCP Version3.8.2
WinSCPWinSCP Version3.8_beta
WinSCPWinSCP Version4.0.4
WinSCPWinSCP Version4.0.5
WinSCPWinSCP Version4.2.6
WinSCPWinSCP Version4.2.7
WinSCPWinSCP Version4.2.8
WinSCPWinSCP Version4.2.9
WinSCPWinSCP Version4.3.2
WinSCPWinSCP Version4.3.4
WinSCPWinSCP Version4.3.5
WinSCPWinSCP Version4.3.6
WinSCPWinSCP Version4.3.7
WinSCPWinSCP Version4.3.8
WinSCPWinSCP Version4.3.9
WinSCPWinSCP Version4.4.0
WinSCPWinSCP Version5.0 Updatebeta
WinSCPWinSCP Version5.0.1 Updatebeta
WinSCPWinSCP Version5.0.2 Updatebeta
WinSCPWinSCP Version5.0.3 Updatebeta
WinSCPWinSCP Version5.0.4 Updatebeta
WinSCPWinSCP Version5.0.5 Updatebeta
WinSCPWinSCP Version5.0.6 Updatebeta
WinSCPWinSCP Version5.0.7 Updatebeta
WinSCPWinSCP Version5.0.8 Updaterc
WinSCPWinSCP Version5.0.9 Updaterc
WinSCPWinSCP Version5.1
WinSCPWinSCP Version5.1.1
WinSCPWinSCP Version5.1.2
WinSCPWinSCP Version5.1.3
WinSCPWinSCP Version5.1.4
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
DebianDebian Linux Version7.1
OpensuseOpensuse Version12.3
PuTTYPuTTY Version0.45
PuTTYPuTTY Version0.46
PuTTYPuTTY Version0.47
PuTTYPuTTY Version0.48
PuTTYPuTTY Version0.49
PuTTYPuTTY Version0.50
PuTTYPuTTY Version0.51
PuTTYPuTTY Version0.52
PuTTYPuTTY Version0.53b
PuTTYPuTTY Version0.54
PuTTYPuTTY Version0.55
PuTTYPuTTY Version0.56
PuTTYPuTTY Version0.57
PuTTYPuTTY Version0.58
PuTTYPuTTY Version0.59
PuTTYPuTTY Version0.60
PuTTYPuTTY Version0.61
PuTTYPuTTY Version2010-06-01 Updater8967 SwEditiondevelopment_snapshot
Simon TathamPutty Version <= 0.62
Simon TathamPutty Version0.53
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.75% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P