CVE-2011-4607: Buffer Overflow
PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords by obtaining access to the process' memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4607?
CVE-2011-4607 has been classified as a moderate severity vulnerability due to its potential for local users to read sensitive information.
How do I fix CVE-2011-4607?
To fix CVE-2011-4607, upgrade to a version of PuTTY higher than 0.61 that does not have this vulnerability.
What versions of PuTTY are affected by CVE-2011-4607?
CVE-2011-4607 affects PuTTY versions 0.59, 0.60, and 0.61.
What type of vulnerability is CVE-2011-4607?
CVE-2011-4607 is a memory management vulnerability that could lead to sensitive information leakage.
Can CVE-2011-4607 impact remote systems?
No, CVE-2011-4607 specifically impacts local users who can access the process memory on affected systems.