Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Gentoo: 200410-29 Normal: PuTTY Pre-authentication Buffer Overflow Risk

gentoo
Calendar Grey October 27, 2004
Scroller Gentoo
A buffer overflow issue in the PuTTY application for Gentoo could allow remote code execution. It is vital to upgrade your system immediately to fix this vulnerability
PuTTY contains a vulnerability allowing an SSH server to execute arbitrary code on the connecting client.

Summary

Gentoo Linux Security Advisory GLSA 200410-29 https://security.gentoo.org/ Severity: Normal Title: PuTTY: Pre-authentication buffer overflow Date: October 27, 2004 Bugs: #69123 ID: 200410-29

Synopsis ======= PuTTY contains a vulnerability allowing an SSH server to execute arbitrary code on the connecting client.
Background ========= PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/putty <= 0.55 >= 0.56
========== PuTTY fails to do proper bounds checking on SSH2_MSG_DEBUG packets. The "stringlen" parameter value is incorr...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround