First published: Thu Mar 21 2019(Updated: )
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/putty | 0.70-6 0.74-1 0.78-2 0.79-1 | |
Putty Putty | <0.71 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Netapp Oncommand Unified Manager | ||
openSUSE Leap | =15.0 | |
<0.71 | ||
=28 | ||
=29 | ||
=8.0 | ||
=9.0 | ||
=15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-9897.
PuTTY versions before 0.71 are affected.
The severity of CVE-2019-9897 is high with a severity value of 7.5.
To fix the vulnerability, you should update PuTTY to version 0.71 or higher, which is not affected.
You can find more information about CVE-2019-9897 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html), [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html), [https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html](https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html).