Vulnerability Name: | CVE-2015-2157 (CCN-101509) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2015-02-28 | ||||||||||||||||||||||||||||||||||||
Published: | 2015-02-28 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-03-21 | ||||||||||||||||||||||||||||||||||||
Summary: | The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-2157 Source: FEDORA Type: UNKNOWN FEDORA-2015-3070 Source: FEDORA Type: UNKNOWN FEDORA-2015-3204 Source: FEDORA Type: UNKNOWN FEDORA-2015-3160 Source: SUSE Type: UNKNOWN openSUSE-SU-2015:0474 Source: CCN Type: oss-security Mailing List, Sat, 28 Feb 2015 12:38:01 +0000 CVE Request: PuTTY fails to clear private key information from memory Source: CCN Type: oss-security Mailing List, Sat, 28 Feb 2015 12:37:10 -0500 (EST) Re: CVE Request: PuTTY fails to clear private key information from memory Source: CONFIRM Type: Patch, Vendor Advisory http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html Source: CCN Type: greenend Web site PuTTY vulnerability private-key-not-wiped-2 Source: CONFIRM Type: Patch, Vendor Advisory http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/private-key-not-wiped-2.html Source: DEBIAN Type: UNKNOWN DSA-3190 Source: MLIST Type: UNKNOWN [oss-security] 20150228 CVE Request: PuTTY fails to clear private key information from memory Source: MLIST Type: UNKNOWN [oss-security] 20150228 Re: CVE Request: PuTTY fails to clear private key information from memory Source: BID Type: UNKNOWN 72825 Source: XF Type: UNKNOWN putty-cve20152157-info-disc(101509) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-2157 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |