Input validation error in PuTTY - CVE-2019-9897
Published: March 21, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31144
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9897
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
Affected software
PuTTY
putty (Alpine package)
putty
Fedora
putty (Alpine package)
putty
Fedora
How to mitigate CVE-2019-9897
Install update from vendor's website.
PuTTY - update to 0.71
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36LWQ3NPFIV7DC7TC4KFPRYRH2OR7SZ2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LDO3F267P347E6U2IILFCYW7JPTLCCES/
- https://seclists.org/bugtraq/2019/Apr/6
- https://security.netapp.com/advisory/ntap-20190404-0001/
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://www.debian.org/security/2019/dsa-4423