CVE-2019-9895: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only
  • Putty Putty: before 0.71 (fixed in 0.71)

Published 2019-03-21. Last modified 2026-06-17.