← Back

CVE-2013-4852

nvd nist
Published: Aug 19, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.

Affected (57)

Products: Winscp: Winscp · Debian: Debian Linux · Opensuse: Opensuse · +2 more
Show all products
1 product
Winscp
1 product
Debian Linux
1 product
Opensuse
1 product
Putty
1 product
Putty
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Winscp
Up to 5.1.5
Version 3.7.6
Version 3.8.2
Version 3.8_beta
Version 4.0.4
Version 4.0.5
Version 4.2.6
Version 4.2.7
Version 4.2.8
Version 4.2.9
Version 4.3.2
Version 4.3.4
Version 4.3.5
Version 4.3.6
Version 4.3.7
Version 4.3.8
Version 4.3.9
Version 4.4.0
Version 5.0.1 beta
Version 5.0.2 beta
Version 5.0.3 beta
Version 5.0.4 beta
Version 5.0.5 beta
Version 5.0.6 beta
Version 5.0.7 beta
Version 5.0.8 rc
Version 5.0.9 rc
Version 5.0 beta
Version 5.1.1
Version 5.1.2
Version 5.1.3
Version 5.1.4
Version 5.1
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0
Version 7.1
Version 12.3
Configuration C
20 vulnerable
Vulnerable SoftwareAffected Versions
Putty
Version 0.45
Version 0.46
Version 0.47
Version 0.48
Version 0.49
Version 0.50
Version 0.51
Version 0.52
Version 0.53b
Version 0.54
Version 0.55
Version 0.56
Version 0.57
Version 0.58
Version 0.59
Version 0.60
Version 0.61
Version 2010-06-01 r8967
Simon Tatham
Up to 0.62
Version 0.53

Related CWEs

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.