CVE-2003-0048: Medium severity Putty PuTTY vulnerability
Published Feb 1, 2003
·Updated
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Affected Software
4 affected components
Putty PuTTY=0.53
Putty PuTTY=0.49
Putty PuTTY=0.53b
Putty PuTTY=0.48
Remediation
Patch Available
Event History
Feb 1, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Feb 19, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0048?
CVE-2003-0048 is considered a high severity vulnerability due to the potential exposure of sensitive SSH credentials.
2
How do I fix CVE-2003-0048?
To fix CVE-2003-0048, upgrade to PuTTY version 0.54 or later, which addresses the issue of not clearing credentials from memory.
3
What software versions are affected by CVE-2003-0048?
CVE-2003-0048 affects PuTTY versions 0.48, 0.49, 0.53, and 0.53b.
4
What type of information can be leaked due to CVE-2003-0048?
CVE-2003-0048 can lead to the leakage of plaintext SSH credentials, including usernames and passwords stored in memory.
5
Who is primarily affected by CVE-2003-0048?
Users of vulnerable versions of PuTTY are primarily affected, especially in environments where memory access can be exploited by attackers.