Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2157
HistoryMar 27, 2015 - 12:00 a.m.

CVE-2015-2157

2015-03-2700:00:00
ubuntu.com
ubuntu.com
17

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51
through 0.63 do not properly wipe SSH-2 private keys from memory, which
allows local users to obtain sensitive information by reading the memory.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchputty< 0.63-4ubuntu0.1UNKNOWN
ubuntu14.10noarchputty< 0.63-8ubuntu0.1UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%