CVE-2019-17069

HIGH

PuTTY < 0.73 - Use-After-Free via SSH1_MSG_DISCONNECT Message

Title source: llm
STIX 2.1

Description

PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.

References (6)

Core 6

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 65.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-416
Status published
Products (4)
netapp/oncommand_unified_manager_core_package
opensuse/leap 15.0
opensuse/leap 15.1
putty/putty < 0.73
Published Oct 01, 2019
Tracked Since Feb 18, 2026