CVE Vulnerabilities

CVE-2013-4852

Published: Aug 19, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
WinscpWinscp*5.1.5 (including)
WinscpWinscp3.7.6 (including)3.7.6 (including)
WinscpWinscp3.8.2 (including)3.8.2 (including)
WinscpWinscp3.8_beta (including)3.8_beta (including)
WinscpWinscp4.0.4 (including)4.0.4 (including)
WinscpWinscp4.0.5 (including)4.0.5 (including)
WinscpWinscp4.2.6 (including)4.2.6 (including)
WinscpWinscp4.2.7 (including)4.2.7 (including)
WinscpWinscp4.2.8 (including)4.2.8 (including)
WinscpWinscp4.2.9 (including)4.2.9 (including)
WinscpWinscp4.3.2 (including)4.3.2 (including)
WinscpWinscp4.3.4 (including)4.3.4 (including)
WinscpWinscp4.3.5 (including)4.3.5 (including)
WinscpWinscp4.3.6 (including)4.3.6 (including)
WinscpWinscp4.3.7 (including)4.3.7 (including)
WinscpWinscp4.3.8 (including)4.3.8 (including)
WinscpWinscp4.3.9 (including)4.3.9 (including)
WinscpWinscp4.4.0 (including)4.4.0 (including)
WinscpWinscp5.0-beta (including)5.0-beta (including)
WinscpWinscp5.0.1-beta (including)5.0.1-beta (including)
WinscpWinscp5.0.2-beta (including)5.0.2-beta (including)
WinscpWinscp5.0.3-beta (including)5.0.3-beta (including)
WinscpWinscp5.0.4-beta (including)5.0.4-beta (including)
WinscpWinscp5.0.5-beta (including)5.0.5-beta (including)
WinscpWinscp5.0.6-beta (including)5.0.6-beta (including)
WinscpWinscp5.0.7-beta (including)5.0.7-beta (including)
WinscpWinscp5.0.8-rc (including)5.0.8-rc (including)
WinscpWinscp5.0.9-rc (including)5.0.9-rc (including)
WinscpWinscp5.1 (including)5.1 (including)
WinscpWinscp5.1.1 (including)5.1.1 (including)
WinscpWinscp5.1.2 (including)5.1.2 (including)
WinscpWinscp5.1.3 (including)5.1.3 (including)
WinscpWinscp5.1.4 (including)5.1.4 (including)
FilezillaUbuntuartful*
FilezillaUbuntulucid*
FilezillaUbuntuprecise*
FilezillaUbuntuquantal*
FilezillaUbunturaring*
FilezillaUbuntusaucy*
FilezillaUbuntuupstream*
FilezillaUbuntuutopic*
FilezillaUbuntuvivid*
FilezillaUbuntuwily*
FilezillaUbuntuyakkety*
FilezillaUbuntuzesty*
PuttyUbuntuartful*
PuttyUbuntubionic*
PuttyUbuntucosmic*
PuttyUbuntudevel*
PuttyUbuntuesm-apps/bionic*
PuttyUbuntuesm-apps/xenial*
PuttyUbuntulucid*
PuttyUbuntuprecise*
PuttyUbuntuquantal*
PuttyUbunturaring*
PuttyUbuntusaucy*
PuttyUbuntutrusty*
PuttyUbuntuupstream*
PuttyUbuntuutopic*
PuttyUbuntuvivid*
PuttyUbuntuwily*
PuttyUbuntuxenial*
PuttyUbuntuyakkety*
PuttyUbuntuzesty*

References