← Back

CVE-2013-4207

nvd nist
Published: Aug 19, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modular inverse and triggers the overflow during a division by zero by the bignum functionality, a different vulnerability than CVE-2013-4206.

Affected (20)

Products: Putty: Putty · Simon Tatham: Putty
1 product
Putty
1 product
Putty
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Putty
Version 0.45
Version 0.46
Version 0.47
Version 0.48
Version 0.49
Version 0.50
Version 0.51
Version 0.52
Version 0.53b
Version 0.54
Version 0.55
Version 0.56
Version 0.57
Version 0.58
Version 0.59
Version 0.60
Version 0.61
Version 2010-06-01 r8967
Simon Tatham
Up to 0.62
Version 0.53

References (12)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.