CVE-2004-1440

Description

Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.466

Associated Vulnerability

VulnerabilityOS Platform
Update WinSCP 3.6.7 to latest versionWindows
Update to PuTTY 0.55Windows
update putty 0.54 to latest versionWindows
Update to PuTTY 0.55(x64)Windows
update putty 0.54 (x64) to latest versionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-341361WinSCP (6.3.5)
PATCH-337645PuTTY (0.81)
PATCH-337645PuTTY (0.81)
PATCH-337646PuTTY (x64) (0.81)
PATCH-337646PuTTY (x64) (0.81)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234