vendor:
Putty
by:
3unnym00n
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Putty
Affected Version From: 0.64
Affected Version To: 0.64
Patch Exists: NO
Related CWE:
CPE: a:putty:putty:0.64
Platforms Tested: Windows 7, Windows XP
2015
putty v0.64 denial of service vulnerability
When doing the ssh dh group exchange old style, if the server sends a malformed dh group exchange reply, it can lead the putty to crash.
Mitigation:
Upgrade to a newer version of PuTTY that includes a fix for this vulnerability.