CVE Vulnerabilities

CVE-2005-0467

Published: Feb 21, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

Affected Software

NameVendorStart VersionEnd Version
PuttyPutty*0.56 (including)
PuttyUbuntudapper*
PuttyUbuntudevel*
PuttyUbuntuedgy*
PuttyUbuntufeisty*

References