CVE-2019-17069
openSUSE Security Advisory - openSUSE-SU-2019:2276-1
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
PuTTY versiones anteriores a 0.73, podrÃa permitir que los servidores remotos SSH-1 causen una denegación de servicio mediante el acceso a ubicaciones de memoria liberadas por medio de un mensaje SSH1_MSG_DISCONNECT.
An update that fixes two vulnerabilities is now available. This update for putty to version 0.73 fixes the following issues. Fixed the insufficient handling of terminal escape sequences, that should delimit the pasted data in bracketed paste mode. Fixed a possible information leak caused by SSH-1 disconnection messages.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-10-01 CVE Reserved
- 2019-10-01 CVE Published
- 2024-08-05 CVE Updated
- 2025-06-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html | Mailing List |
|
https://lists.tartarus.org/pipermail/putty-announce/2019/000029.html | Mailing List | |
https://security.netapp.com/advisory/ntap-20191127-0003 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Putty Search vendor "Putty" | Putty Search vendor "Putty" for product "Putty" | < 0.73 Search vendor "Putty" for product "Putty" and version " < 0.73" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.0 Search vendor "Opensuse" for product "Leap" and version "15.0" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Oncommand Unified Manager Core Package Search vendor "Netapp" for product "Oncommand Unified Manager Core Package" | - | - |
Affected
|