CVE-2003-0048
EPSS 0.08%
Description
PuTTY 0.53b and earlier does not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
How to fix CVE-2003-0048
To remediate CVE-2003-0048, upgrade the affected package to a fixed version below.
- Debian/putty—upgrade to 0.53-b-2003-01-04-1 or later
Is CVE-2003-0048 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.53-b-2003-01-04-1