First published: Tue Oct 01 2019(Updated: )
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PuTTY | <0.73 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
NetApp OnCommand Unified Manager for Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17069 is a vulnerability in PuTTY before version 0.73 that allows remote SSH-1 servers to cause a denial of service.
CVE-2019-17069 affects PuTTY versions before 0.73.
CVE-2019-17069 has a severity rating of high with a CVSS score of 7.5.
CVE-2019-17069 can be exploited by sending a specially crafted SSH1_MSG_DISCONNECT message to the vulnerable server.
Yes, the fix for CVE-2019-17069 is to update PuTTY to version 0.73 or later.