← Back

CVE-2015-5309

nvd nist
Published: Dec 7, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer underflow.

Affected (4)

2 products
Leap
Opensuse
1 product
Putty
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Opensuse
Version 13.1
Version 13.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.65

Related CWEs

Timeline

No history available yet.