Vulnerability Description
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 9Bis | Kitty | <= 0.66.6.3 |
| Simon Tatham | Putty | <= 0.66 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00131.html
- http://seclists.org/fulldisclosure/2016/Mar/22
- http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-pscp-sink-sscanfPatch
- http://www.securityfocus.com/bid/84296
- http://www.securitytracker.com/id/1035257
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-2563Vendor Advisory
- https://security.gentoo.org/glsa/201606-01
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00131.html
- http://seclists.org/fulldisclosure/2016/Mar/22
- http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-pscp-sink-sscanfPatch
- http://www.securityfocus.com/bid/84296
- http://www.securitytracker.com/id/1035257
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-2563Vendor Advisory
- https://security.gentoo.org/glsa/201606-01
FAQ
What is CVE-2016-2563?
CVE-2016-2563 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute ...
How severe is CVE-2016-2563?
CVE-2016-2563 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2563?
Check the references section above for vendor advisories and patch information. Affected products include: 9Bis Kitty, Simon Tatham Putty.