1.9
CVSSv2

CVE-2006-7162

Published: 07/03/2007 Updated: 05/09/2008
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

PuTTY 0.59 and previous versions uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files.

Vulnerable Product Search on Vulmon Subscribe to Product

putty putty

Vendor Advisories

Debian Bug report logs - #400804 putty-tools: puttygen can create world-readable private keys Package: putty-tools; Maintainer for putty-tools is Colin Watson <cjwatson@debianorg>; Source for putty-tools is src:putty (PTS, buildd, popcon) Reported by: Daniel Kahn Gillmor <dkg-debianorg@fifthhorsemannet> Date: Tue, ...