CVE-2013-4208
EPSS 0.06%
Description
The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
How to fix CVE-2013-4208
To remediate CVE-2013-4208, upgrade the affected package to a fixed version below.
- Debian/filezilla—upgrade to 3.7.3-1 or later
- Debian/putty—upgrade to 0.63-1 or later
Is CVE-2013-4208 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.7.3-1
- from 0, < 0.63-1