Lucene search

K
kasperskyKaspersky LabKLA11445
HistoryDec 07, 2015 - 12:00 a.m.

KLA11445 ACE vulnerability in PuTTY

2015-12-0700:00:00
Kaspersky Lab
threats.kaspersky.com
28

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.9

Confidence

Low

EPSS

0.022

Percentile

89.7%

Integer overflow vulnerability was found in PuTTY. Malicious users can exploit this vulnerability remotely to execute arbitrary code and cause denial of service.

Original advisories

PuTTY vulnerability vuln-ech-overflow

Related products

PuTTY

CVE list

CVE-2015-5309 warning

Solution

Update to the latest version

Download PuTTY

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • PuTTY earlier than 0.66

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

7.9

Confidence

Low

EPSS

0.022

Percentile

89.7%