Vulnerability Name: | CVE-2013-4208 (CCN-86268) | ||||||||||||||||||||||||
Assigned: | 2013-08-06 | ||||||||||||||||||||||||
Published: | 2013-08-06 | ||||||||||||||||||||||||
Updated: | 2019-03-21 | ||||||||||||||||||||||||
Summary: | The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||
References: | Source: CCN Type: tortoisegit GIT Repository Release 1.8.5.0 Source: MITRE Type: CNA CVE-2013-4208 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1347 Source: CCN Type: oss-sec mailing list, Tue, 06 Aug 2013 17:45:13 -0600 Re: CVE request: three additional flaws fixed in putty 0.63 Source: SECUNIA Type: Vendor Advisory 54379 Source: CCN Type: SA54415 FileZilla Client PuTTY Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 54533 Source: CCN Type: SA54599 TortoiseGit PuTTY PLink Multiple Integer Overflow Vulnerabilities Source: CCN Type: PuTTY SVN Repository Revision 9988 Source: CCN Type: PuTTY Web Site PuTTY Download Page Source: CONFIRM Type: UNKNOWN http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/private-key-not-wiped.html Source: DEBIAN Type: UNKNOWN DSA-2736 Source: DEBIAN Type: DSA-2736 putty -- several vulnerabilities Source: MLIST Type: UNKNOWN [oss-security] 20130806 CVE request: three additional flaws fixed in putty 0.63 Source: CCN Type: BID-61644 PuTTY Private Key 'putty/sshdss.c' Multiple Information Disclosure Vulnerabilities Source: XF Type: UNKNOWN putty-cve20134208-info-disc(86268) Source: CCN Type: FileZilla Web Site FileZilla Client 3.7.3 released Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4208 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |