← Back

CVE-2015-2157

nvd nist
Published: Mar 27, 2015Modified: May 6, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

Affected (19)

Show all products
1 product
Debian Linux
1 product
Fedora
1 product
Opensuse
1 product
Putty
1 product
Putty
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Fedoraproject
Version 20
Version 22
Opensuse
Version 13.1
Version 13.2
Configuration B
14 vulnerable
Vulnerable SoftwareAffected Versions
Putty
Version 0.51
Version 0.52
Version 0.53b
Version 0.54
Version 0.55
Version 0.56
Version 0.57
Version 0.58
Version 0.59
Version 0.60
Version 0.61
Version 0.62
Version 0.63
Version 0.53

References (20)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.