← Back to CVE List
Vulnerability Intelligence Report

CVE-2004-1008

Integer signedness error in the ssh2_rdpkt function in PuTTY before 0.56 allows remote attackers to execute arbitrary code via a SSH2_MSG_DEBUG packet with a modified stringlen parameter, which leads to a buffer overflow.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:7.36%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
putty putty 0.48, 0.49, 0.50, 0.51, 0.52, 0.53, 0.53b, 0.54, 0.55
tortoisecvs tortoisecvs 1.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
7.363%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2004-11-03T00:00:00
Published2004-12-01T05:00:00
Patch Date2004-10-27
Last Updated2024-08-08T00:39:00

LINK COPIED TO CLIPBOARD