CVE-2019-9894: High severity putty vulnerability
Published Mar 21, 2019
·Updated
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
Affected Software
8 affected componentsFixes available
debian/putty
0.70-60.74-10.78-20.79-1
Putty PuTTY<0.71
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
NetApp OnCommand Unified Manager
openSUSE Leap=15.0
Remediation
Patch Available
Event History
Mar 21, 2019
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
Description
Data Sourced
via NVD·04:01 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-9894?
CVE-2019-9894 is a vulnerability in PuTTY before version 0.71 that allows for a remotely triggerable memory overwrite in the RSA key exchange process.
2
How does CVE-2019-9894 affect PuTTY?
CVE-2019-9894 affects PuTTY versions before 0.71, potentially leading to a memory overwrite in the RSA key exchange.
3
What is the severity of CVE-2019-9894?
The severity of CVE-2019-9894 is high with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2019-9894?
PuTTY versions before 0.71 are affected by CVE-2019-9894.
5
How can I fix CVE-2019-9894?
To fix CVE-2019-9894, update PuTTY to version 0.71 or later.