CVE-2013-4208

The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:putty:putty:0.45:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.46:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.47:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.49:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.50:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.51:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.52:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.53b:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.54:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.55:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.56:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.57:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.58:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.59:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.60:*:*:*:*:*:*:*
cpe:2.3:a:putty:putty:0.61:*:*:*:*:*:*:*
cpe:2.3:a:simon_tatham:putty:*:*:*:*:*:*:*:*
cpe:2.3:a:simon_tatham:putty:0.53:*:*:*:*:*:*:*

History

21 Nov 2024, 01:55

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-updates/2013-08/msg00035.html - () http://lists.opensuse.org/opensuse-updates/2013-08/msg00035.html -
References () http://secunia.com/advisories/54379 - Vendor Advisory () http://secunia.com/advisories/54379 - Vendor Advisory
References () http://secunia.com/advisories/54533 - () http://secunia.com/advisories/54533 -
References () http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/private-key-not-wiped.html - () http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/private-key-not-wiped.html -
References () http://www.debian.org/security/2013/dsa-2736 - () http://www.debian.org/security/2013/dsa-2736 -
References () http://www.openwall.com/lists/oss-security/2013/08/06/11 - () http://www.openwall.com/lists/oss-security/2013/08/06/11 -

Information

Published : 2013-08-19 23:55

Updated : 2024-11-21 01:55


NVD link : CVE-2013-4208

Mitre link : CVE-2013-4208

CVE.ORG link : CVE-2013-4208


JSON object : View

Products Affected

simon_tatham

  • putty

putty

  • putty
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor