Resource management error in PuTTY - CVE-2019-17069
Published: October 7, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing SSH1_MSG_DISCONNECT message. A remote attacker can trick the victim to connect to a remote SSH-1 server, send a specially crafted SSH1_MSG_DISCONNECT message and crash the affected PuTTY client.
Affected software
putty (Alpine package)
SUSE Linux
Opensuse
How to mitigate CVE-2019-17069
putty (Alpine package) - update to 0.73-r0