CVE-2005-0467: Integer Overflow
Multiple integer overflows in the (1) sftppktgetstring and (2) fxpreaddirrecv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0467?
CVE-2005-0467 is considered a critical vulnerability due to its potential to allow arbitrary code execution from remote web sites.
How do I fix CVE-2005-0467?
To fix CVE-2005-0467, update PuTTY to version 0.57 or later to eliminate the integer overflow vulnerabilities.
What versions of PuTTY are affected by CVE-2005-0467?
CVE-2005-0467 affects PuTTY versions up to and including 0.56.
What functions are involved in the CVE-2005-0467 vulnerability?
The vulnerability in CVE-2005-0467 involves integer overflows in the sftp_pkt_getstring and fxp_readdir_recv functions.
Can CVE-2005-0467 be exploited remotely?
Yes, CVE-2005-0467 can be exploited remotely by malicious websites via crafted SFTP responses.