CVE-2017-6542: Buffer Overflow
The sshagentchanneldata function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6542?
CVE-2017-6542 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-6542?
To mitigate CVE-2017-6542, upgrade to PuTTY version 0.68 or later.
What software is affected by CVE-2017-6542?
CVE-2017-6542 affects PuTTY versions prior to 0.68 and specific versions of openSUSE Leap.
Can CVE-2017-6542 be exploited remotely?
Yes, CVE-2017-6542 can be exploited remotely if an attacker can connect to the Unix-domain socket of the forwarded agent.
What kind of attack does CVE-2017-6542 enable?
CVE-2017-6542 enables a buffer overflow attack that can lead to various unspecified impacts on the affected systems.