CVE-2015-2157
putty - security update
EPSS 0.13%
Description
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
How to fix CVE-2015-2157
To remediate CVE-2015-2157, upgrade the affected package to a fixed version below.
- Debian/putty—upgrade to 0.63-10 or later
- Debian/putty—upgrade to 0.60+2010-02-20-1+squeeze3 or later
- Debian/putty—upgrade to 0.62-9+deb7u2 or later
Is CVE-2015-2157 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 0.63-10
- from 0, < 0.60+2010-02-20-1+squeeze3
- from 0, < 0.62-9+deb7u2