Lucene search

K
cveMitreCVE-2004-1008
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1008

2005-01-1005:00:00
mitre
web.nvd.nist.gov
56
cve-2004-1008
putty
buffer overflow
ssh2
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.121

Percentile

95.4%

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

Affected configurations

Nvd
Node
puttyputtyMatch0.48
OR
puttyputtyMatch0.49
OR
puttyputtyMatch0.50
OR
puttyputtyMatch0.51
OR
puttyputtyMatch0.52
OR
puttyputtyMatch0.53
OR
puttyputtyMatch0.53b
OR
puttyputtyMatch0.54
OR
puttyputtyMatch0.55
OR
tortoisecvstortoisecvsMatch1.8
VendorProductVersionCPE
puttyputty0.48cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:*
puttyputty0.49cpe:2.3:a:putty:putty:0.49:*:*:*:*:*:*:*
puttyputty0.50cpe:2.3:a:putty:putty:0.50:*:*:*:*:*:*:*
puttyputty0.51cpe:2.3:a:putty:putty:0.51:*:*:*:*:*:*:*
puttyputty0.52cpe:2.3:a:putty:putty:0.52:*:*:*:*:*:*:*
puttyputty0.53cpe:2.3:a:putty:putty:0.53:*:*:*:*:*:*:*
puttyputty0.53bcpe:2.3:a:putty:putty:0.53b:*:*:*:*:*:*:*
puttyputty0.54cpe:2.3:a:putty:putty:0.54:*:*:*:*:*:*:*
puttyputty0.55cpe:2.3:a:putty:putty:0.55:*:*:*:*:*:*:*
tortoisecvstortoisecvs1.8cpe:2.3:a:tortoisecvs:tortoisecvs:1.8:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.121

Percentile

95.4%