CVE Vulnerabilities

CVE-2004-1008

Published: Jan 10, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
PuttyPutty0.48 (including)0.48 (including)
PuttyPutty0.49 (including)0.49 (including)
PuttyPutty0.50 (including)0.50 (including)
PuttyPutty0.51 (including)0.51 (including)
PuttyPutty0.52 (including)0.52 (including)
PuttyPutty0.53 (including)0.53 (including)
PuttyPutty0.53b (including)0.53b (including)
PuttyPutty0.54 (including)0.54 (including)
PuttyPutty0.55 (including)0.55 (including)
TortoisecvsTortoisecvs1.8 (including)1.8 (including)

References