CVE-2013-4852: Debian Linux

Medium severity, CVSS 6.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 7.1 only
  • Opensuse Opensuse: version 12.3 only
  • Putty Putty: version 0.45 only; version 0.46 only; version 0.47 only; version 0.48 only; version 0.49 only; version 0.50 only; …
  • Simon Tatham Putty: up to and including 0.62; version 0.53 only
  • Winscp Winscp: up to and including 5.1.5; version 3.7.6 only; version 3.8.2 only; version 3.8_beta only; version 4.0.4 only; version 4.0.5 only; …

Published 2013-08-19. Last modified 2026-06-16.