Heap-based Buffer Underflow in PuTTY Affects Remote SSH Functionality
CVE-2013-4206

Currently unrated

Key Information:

Vendor

Putty

Status
Vendor
CVE Published:
19 August 2013

What is CVE-2013-4206?

The vulnerability arises from a heap-based buffer underflow in the modmul function within PuTTY's sshbn.c file. This issue permits remote SSH servers to exploit a crafted DSA signature, potentially leading to denial of service or memory corruption. The flaw occurs during certain bit-shifting operations essential for modular multiplication, which are improperly handled, thus exposing the application to crash or unintended code execution.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.