Lucene search

K
cve[email protected]CVE-2015-2157
HistoryMar 27, 2015 - 2:59 p.m.

CVE-2015-2157

2015-03-2714:59:05
CWE-200
web.nvd.nist.gov
40
putty
ssh2_load_userkey
ssh2_save_userkey
vulnerability
cve-2015-2157
nvd
security

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

Affected configurations

NVD
Node
debiandebian_linuxMatch7.0
OR
fedoraprojectfedoraMatch20
OR
fedoraprojectfedoraMatch22
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
puttyputtyMatch0.51
OR
puttyputtyMatch0.52
OR
puttyputtyMatch0.53b
OR
puttyputtyMatch0.54
OR
puttyputtyMatch0.55
OR
puttyputtyMatch0.56
OR
puttyputtyMatch0.57
OR
puttyputtyMatch0.58
OR
puttyputtyMatch0.59
OR
puttyputtyMatch0.60
OR
puttyputtyMatch0.61
OR
puttyputtyMatch0.62
OR
puttyputtyMatch0.63
OR
simon_tathamputtyMatch0.53

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%