CVE-2015-2157: Infoleak
Published Mar 27, 2015
·Updated
The (1) ssh2loaduserkey and (2) ssh2saveuserkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
Affected Software
19 affected components
Debian Debian Linux=7.0
Fedoraproject Fedora=20
Fedoraproject Fedora=22
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Putty PuTTY=0.51
Putty PuTTY=0.52
Putty PuTTY=0.53b
Putty PuTTY=0.54
Putty PuTTY=0.55
Putty PuTTY=0.56
Putty PuTTY=0.57
Putty PuTTY=0.58
Putty PuTTY=0.59
Putty PuTTY=0.60
Putty PuTTY=0.61
Putty PuTTY=0.62
Putty PuTTY=0.63
Simon Tatham Putty=0.53
Remediation
Event History
Mar 27, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2157?
CVE-2015-2157 has a medium severity level due to its potential to expose sensitive information from memory.
2
How do I fix CVE-2015-2157?
To fix CVE-2015-2157, upgrade PuTTY to a version later than 0.63 that addresses the memory wiping issue.
3
Which versions of PuTTY are affected by CVE-2015-2157?
PuTTY versions from 0.51 to 0.63 are affected by CVE-2015-2157.
4
Can local users exploit CVE-2015-2157?
Yes, local users can exploit CVE-2015-2157 to read sensitive SSH-2 private keys from memory.
5
Is CVE-2015-2157 specific to any operating system?
CVE-2015-2157 affects multiple operating systems, including Debian and Fedora, using vulnerable versions of PuTTY.