First published: Tue Oct 01 2019(Updated: )
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PuTTY | <0.73 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17067 is a vulnerability in PuTTY versions before 0.73 on Windows that improperly opens port-forwarding listening sockets.
The severity of CVE-2019-17067 is critical with a CVSS severity score of 9.8.
CVE-2019-17067 affects PuTTY versions before 0.73 on Windows by allowing attackers to listen on the same port as the port-forwarding listening sockets, enabling them to steal incoming connections.
To fix CVE-2019-17067, update PuTTY to version 0.73 or newer.
More information about CVE-2019-17067 can be found at the following references: [link1](https://lists.tartarus.org/pipermail/putty-announce/2019/000029.html) and [link2](https://security.netapp.com/advisory/ntap-20191127-0003/).