Integer Overflow vulnerability in PuTTY and WinSCP via a negative size valueID: oval:org.secpod.oval:def:15942 | Date: (C)2013-11-10 (M)2023-03-24 |
Class: VULNERABILITY | Family: windows |
The host is installed with WinSCP before 5.1.6 or PuTTY 0.62 and earlier and is prone to an integer overflow vulnerability. The flaw is present in the application, which fails to handle a negative size value in an RSA key signature during the SSH handshake. Successful exploitation could allow attackers to crash the service.
Platform: |
Microsoft Windows Server 2022 |
Microsoft Windows 11 |
Microsoft Windows Server 2019 |
Microsoft Windows Server 2016 |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows 10 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2003 |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Vista |
Microsoft Windows XP |