CVE Vulnerabilities

CVE-2004-1008

Published: Jan 10, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

Affected Software

Name Vendor Start Version End Version
Putty Putty 0.48 (including) 0.48 (including)
Putty Putty 0.49 (including) 0.49 (including)
Putty Putty 0.50 (including) 0.50 (including)
Putty Putty 0.51 (including) 0.51 (including)
Putty Putty 0.52 (including) 0.52 (including)
Putty Putty 0.53 (including) 0.53 (including)
Putty Putty 0.53b (including) 0.53b (including)
Putty Putty 0.54 (including) 0.54 (including)
Putty Putty 0.55 (including) 0.55 (including)
Tortoisecvs Tortoisecvs 1.8 (including) 1.8 (including)

References