CVE-2013-4207: Putty

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modular inverse and triggers the overflow during a division by zero by the bignum functionality, a different vulnerability than CVE-2013-4206.

Affected products

  • Putty Putty: version 0.45 only; version 0.46 only; version 0.47 only; version 0.48 only; version 0.49 only; version 0.50 only; …
  • Simon Tatham Putty: up to and including 0.62; version 0.53 only

Published 2013-08-19. Last modified 2026-06-16.