5
CVSSv2

CVE-2019-9897

Published: 21/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions prior to 0.71.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

putty putty

fedoraproject fedora 28

fedoraproject fedora 29

debian debian linux 8.0

debian debian linux 9.0

netapp oncommand unified manager -

opensuse leap 15.0

Vendor Advisories

Multiple vulnerabilities were found in the PuTTY SSH client, which could result in denial of service and potentially the execution of arbitrary code In addition, in some situations random numbers could potentially be re-used For the stable distribution (stretch), these problems have been fixed in version 067-3+deb9u1 We recommend that you upgra ...

Github Repositories

CVE-2019-9897 PuTTY 070 and older Denial-of-Service PoC contains 2 different approaches, one to generate a file which contains over 2MB worth of unicode combining characters; and two a simple TCP server which sends the same amount of combining characters over a socket Includes a simple client to ensure the server is sending correctly Running the server script ruby serverr