CVE-2013-4208: Infoleak
The rsaverify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4208?
CVE-2013-4208 is classified as a high severity vulnerability due to the potential exposure of sensitive cryptographic keys.
How do I fix CVE-2013-4208?
To fix CVE-2013-4208, upgrade PuTTY to version 0.63 or later where the vulnerability has been addressed.
Who is affected by CVE-2013-4208?
Local users running PuTTY versions prior to 0.63 are affected by CVE-2013-4208.
What are the risks associated with CVE-2013-4208?
The risks associated with CVE-2013-4208 include potential unauthorized access to private RSA and DSA keys.
Is there a workaround for CVE-2013-4208?
While upgrading is the recommended solution for CVE-2013-4208, minimizing local access can reduce the risk temporarily.