Vulnerability Details CVE-2015-5309
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which triggers a buffer underflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 83.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-5309
-
cpe:2.3:a:simon_tatham:putty:-
-
cpe:2.3:a:simon_tatham:putty:0.45
-
cpe:2.3:a:simon_tatham:putty:0.46
-
cpe:2.3:a:simon_tatham:putty:0.47
-
cpe:2.3:a:simon_tatham:putty:0.48
-
cpe:2.3:a:simon_tatham:putty:0.49
-
cpe:2.3:a:simon_tatham:putty:0.50
-
cpe:2.3:a:simon_tatham:putty:0.51
-
cpe:2.3:a:simon_tatham:putty:0.52
-
cpe:2.3:a:simon_tatham:putty:0.53
-
cpe:2.3:a:simon_tatham:putty:0.53b
-
cpe:2.3:a:simon_tatham:putty:0.54
-
cpe:2.3:a:simon_tatham:putty:0.55
-
cpe:2.3:a:simon_tatham:putty:0.56
-
cpe:2.3:a:simon_tatham:putty:0.57
-
cpe:2.3:a:simon_tatham:putty:0.58
-
cpe:2.3:a:simon_tatham:putty:0.59
-
cpe:2.3:a:simon_tatham:putty:0.60
-
cpe:2.3:a:simon_tatham:putty:0.61
-
cpe:2.3:a:simon_tatham:putty:0.62
-
cpe:2.3:a:simon_tatham:putty:0.63
-
cpe:2.3:a:simon_tatham:putty:0.65
-
cpe:2.3:o:opensuse:leap:42.1
-
cpe:2.3:o:opensuse:opensuse:13.1
-
cpe:2.3:o:opensuse:opensuse:13.2