CVE-2004-1008

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.49:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.50:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.51:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.52:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.53:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.53b:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.54:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.55:*:*:*:*:*:*:*
cpe:2.3:a:tortoisecvs:tortoisecvs:1.8:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=109889312917613&w=2 - () http://marc.info/?l=bugtraq&m=109889312917613&w=2 -
References () http://secunia.com/advisories/12987/ - () http://secunia.com/advisories/12987/ -
References () http://secunia.com/advisories/13012/ - () http://secunia.com/advisories/13012/ -
References () http://secunia.com/advisories/17214 - () http://secunia.com/advisories/17214 -
References () http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414 - () http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002414 -
References () http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416 - () http://www-1.ibm.com/support/docview.wss?uid=ssg1S1002416 -
References () http://www.chiark.greenend.org.uk/~sgtatham/putty/ - () http://www.chiark.greenend.org.uk/~sgtatham/putty/ -
References () http://www.gentoo.org/security/en/glsa/glsa-200410-29.xml - Patch, Vendor Advisory () http://www.gentoo.org/security/en/glsa/glsa-200410-29.xml - Patch, Vendor Advisory
References () http://www.idefense.com/application/poi/display?id=155&type=vulnerabilities&flashstatus=true - () http://www.idefense.com/application/poi/display?id=155&type=vulnerabilities&flashstatus=true -
References () http://www.securityfocus.com/bid/11549 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/11549 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17886 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17886 -

Information

Published : 2005-01-10 05:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-1008

Mitre link : CVE-2004-1008

CVE.ORG link : CVE-2004-1008


JSON object : View

Products Affected

tortoisecvs

  • tortoisecvs

putty

  • putty