CVE-2013-4206: Putty
Medium severity, CVSS 6.8. EPSS: 2.5% chance of exploitation in the next 30 days.
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execution via a crafted DSA signature, which is not properly handled when performing certain bit-shifting operations during modular multiplication.
Affected products
- Putty Putty: version 0.45 only; version 0.46 only; version 0.47 only; version 0.48 only; version 0.49 only; version 0.50 only; …
- Simon Tatham Putty: up to and including 0.62; version 0.53 only
Published 2013-08-19. Last modified 2026-06-16.