CVE-2013-4206: Buffer Overflow
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execution via a crafted DSA signature, which is not properly handled when performing certain bit-shifting operations during modular multiplication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4206?
CVE-2013-4206 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2013-4206?
To fix CVE-2013-4206, you should upgrade to PuTTY version 0.63 or later.
What software is affected by CVE-2013-4206?
CVE-2013-4206 affects PuTTY versions up to 0.62.
Can CVE-2013-4206 potentially lead to code execution?
Yes, CVE-2013-4206 may allow remote servers to trigger memory corruption or even code execution.
Is CVE-2013-4206 a local or remote vulnerability?
CVE-2013-4206 is a remote vulnerability, allowing attackers to exploit it via crafted DSA signatures.