Vulnerability Details CVE-2013-4206
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execution via a crafted DSA signature, which is not properly handled when performing certain bit-shifting operations during modular multiplication.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.4%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2013-4206
-
cpe:2.3:a:putty:putty:0.45
-
cpe:2.3:a:putty:putty:0.46
-
cpe:2.3:a:putty:putty:0.47
-
cpe:2.3:a:putty:putty:0.48
-
cpe:2.3:a:putty:putty:0.49
-
cpe:2.3:a:putty:putty:0.50
-
cpe:2.3:a:putty:putty:0.51
-
cpe:2.3:a:putty:putty:0.52
-
cpe:2.3:a:putty:putty:0.53b
-
cpe:2.3:a:putty:putty:0.54
-
cpe:2.3:a:putty:putty:0.55
-
cpe:2.3:a:putty:putty:0.56
-
cpe:2.3:a:putty:putty:0.57
-
cpe:2.3:a:putty:putty:0.58
-
cpe:2.3:a:putty:putty:0.59
-
cpe:2.3:a:putty:putty:0.60
-
cpe:2.3:a:putty:putty:0.61
-
cpe:2.3:a:putty:putty:2010-06-01
-
cpe:2.3:a:simon_tatham:putty:-
-
cpe:2.3:a:simon_tatham:putty:0.45
-
cpe:2.3:a:simon_tatham:putty:0.46
-
cpe:2.3:a:simon_tatham:putty:0.47
-
cpe:2.3:a:simon_tatham:putty:0.48
-
cpe:2.3:a:simon_tatham:putty:0.49
-
cpe:2.3:a:simon_tatham:putty:0.50
-
cpe:2.3:a:simon_tatham:putty:0.51
-
cpe:2.3:a:simon_tatham:putty:0.52
-
cpe:2.3:a:simon_tatham:putty:0.53
-
cpe:2.3:a:simon_tatham:putty:0.53b
-
cpe:2.3:a:simon_tatham:putty:0.54
-
cpe:2.3:a:simon_tatham:putty:0.55
-
cpe:2.3:a:simon_tatham:putty:0.56
-
cpe:2.3:a:simon_tatham:putty:0.57
-
cpe:2.3:a:simon_tatham:putty:0.58
-
cpe:2.3:a:simon_tatham:putty:0.59
-
cpe:2.3:a:simon_tatham:putty:0.60
-
cpe:2.3:a:simon_tatham:putty:0.61
-
cpe:2.3:a:simon_tatham:putty:0.62