Subscribe to Windows IT Pro
October 28, 2004 12:00 AM

Arbitrary Code Execution in PuTTY for Windows

Windows IT Pro
InstantDoc ID #44358
Rating: (1)

Reported October 28, 2004, by  iDEFENSE

VERSIONS AFFECTED

  • PuTTY 0.55 and earlier

DESCRIPTION
A vulnerability in the Telnet/Secure Shell (SSH) program PuTTY could result in the remote execution of arbitrary code on the vulnerable system. This vulnerability is a result of insufficient bounds checking on SSH2_MSG_DEBUG packets. The stringlen parameter obtains a user-supplied value by reading in an integer from an offset in the packet data. Signedness problems cause the stringlen value to be incorrectly checked.

VENDOR RESPONSE
The author, Simon Tatham, has released PuTTY 0.56 to address this vulnerability.

CREDIT
Discovered by iDEFENSE.

Related Content:

ARTICLE TOOLS

Comments
  • PAUL THURR0TT
    8 years ago
    Nov 03, 2004

    Great article. Better than mine!

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.