CVE-2019-9895: Buffer Overflow
Published Mar 21, 2019
·Updated
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
Affected Software
7 affected componentsFixes available
debian/putty
0.70-60.74-10.78-20.79-1
All of the following
Putty PuTTY<0.71
Opengroup Unix
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Putty PuTTY<0.71
Opengroup Unix
Event History
Mar 21, 2019
CVE Published
via MITRE·02:31 AM
Data Sourced
via MITRE·02:31 AM
Description
Data Sourced
via NVD·04:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this PuTTY vulnerability?
The vulnerability ID for this PuTTY vulnerability is CVE-2019-9895.
2
What is the severity of CVE-2019-9895?
The severity of CVE-2019-9895 is critical with a CVSS score of 9.8.
3
What is the description of CVE-2019-9895?
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
4
What software versions are affected by CVE-2019-9895?
PuTTY versions before 0.71 on Unix are affected by CVE-2019-9895.
5
How can I fix CVE-2019-9895?
Upgrade to PuTTY version 0.71 or later to fix CVE-2019-9895.