CVE-2019-17069: Use After Free
Published Oct 1, 2019
·Updated
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1MSGDISCONNECT message.
Affected Software
4 affected components
Putty PuTTY<0.73
openSUSE Leap=15.0
openSUSE Leap=15.1
NetApp OnCommand Unified Manager Core Package
Event History
Oct 1, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2019-17069?
CVE-2019-17069 is a vulnerability in PuTTY before version 0.73 that allows remote SSH-1 servers to cause a denial of service.
2
How does CVE-2019-17069 affect PuTTY?
CVE-2019-17069 affects PuTTY versions before 0.73.
3
What is the severity of CVE-2019-17069?
CVE-2019-17069 has a severity rating of high with a CVSS score of 7.5.
4
How can CVE-2019-17069 be exploited?
CVE-2019-17069 can be exploited by sending a specially crafted SSH1_MSG_DISCONNECT message to the vulnerable server.
5
Is there a fix for CVE-2019-17069?
Yes, the fix for CVE-2019-17069 is to update PuTTY to version 0.73 or later.