MEDIUM · 6.8

CVE-2013-4852

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in...

Vulnerability Description

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
WinscpWinscp<= 5.1.5
DebianDebian Linux6.0
OpensuseOpensuse12.3
PuttyPutty0.45
Simon TathamPutty<= 0.62

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4852?

CVE-2013-4852 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in...

How severe is CVE-2013-4852?

CVE-2013-4852 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4852?

Check the references section above for vendor advisories and patch information. Affected products include: Winscp Winscp, Debian Debian Linux, Opensuse Opensuse, Putty Putty, Simon Tatham Putty.