PuTTY Two Integer Overflow Vulnerabilities
- 0
- Add a Comment
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Gaël Delalleau has reported two vulnerabilities in PuTTY, which can be exploited by malicious people to compromise a user’s system.
1) An integer overflow in the “fxp_readdir_recv()” function in “sftp.c” can be exploited to execute arbitrary code via a malicious SFTP (SSH File Transfer Protocol) server sending a specially crafted respond to the “FXP_READDIR” command.
2) An integer overflow in the “fxp_open_recv()” function in “sftp.c” can be exploited to execute arbitrary code via a malicious SFTP server sending a specially crafted string field.
NOTE: Successful exploitation is only possible after host key verification.
The vulnerabilities have been reported in versions prior to 0.57.
Solution: Update to version 0.57.
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html“
Full article: Secunia Advisory: SA14333
