Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2015-2157

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.0%
CVSS Severity
CVSS v2 Score 2.1
References
Products affected by CVE-2015-2157
  • Putty » Putty » Version: 0.51
    cpe:2.3:a:putty:putty:0.51
  • Putty » Putty » Version: 0.52
    cpe:2.3:a:putty:putty:0.52
  • Putty » Putty » Version: 0.53b
    cpe:2.3:a:putty:putty:0.53b
  • Putty » Putty » Version: 0.54
    cpe:2.3:a:putty:putty:0.54
  • Putty » Putty » Version: 0.55
    cpe:2.3:a:putty:putty:0.55
  • Putty » Putty » Version: 0.56
    cpe:2.3:a:putty:putty:0.56
  • Putty » Putty » Version: 0.57
    cpe:2.3:a:putty:putty:0.57
  • Putty » Putty » Version: 0.58
    cpe:2.3:a:putty:putty:0.58
  • Putty » Putty » Version: 0.59
    cpe:2.3:a:putty:putty:0.59
  • Putty » Putty » Version: 0.60
    cpe:2.3:a:putty:putty:0.60
  • Putty » Putty » Version: 0.61
    cpe:2.3:a:putty:putty:0.61
  • Putty » Putty » Version: 0.62
    cpe:2.3:a:putty:putty:0.62
  • Putty » Putty » Version: 0.63
    cpe:2.3:a:putty:putty:0.63
  • Simon Tatham » Putty » Version: 0.53
    cpe:2.3:a:simon_tatham:putty:0.53
  • Debian » Debian Linux » Version: 7.0
    cpe:2.3:o:debian:debian_linux:7.0
  • Fedoraproject » Fedora » Version: 20
    cpe:2.3:o:fedoraproject:fedora:20
  • Fedoraproject » Fedora » Version: 22
    cpe:2.3:o:fedoraproject:fedora:22
  • Opensuse » Opensuse » Version: 13.1
    cpe:2.3:o:opensuse:opensuse:13.1
  • Opensuse » Opensuse » Version: 13.2
    cpe:2.3:o:opensuse:opensuse:13.2


Contact Us

Shodan ® - All rights reserved