Vulnerability Intelligence Report
CVE-2004-1008
Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:7.36%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| putty | putty | 0.48, 0.49, 0.50, 0.51, 0.52, 0.53, 0.53b, 0.54, 0.55 |
| tortoisecvs | tortoisecvs | 1.8 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
7.363%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2004-11-03T00:00:00 |
| Published | 2004-12-01T05:00:00 |
| Patch Date | 2004-10-27 |
| Last Updated | 2024-08-08T00:39:00 |
Community Chatter & Buzz