Candidate: CVE-2016-2563 PublicDate: 2016-04-07 23:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2563 http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-pscp-sink-sscanf.html http://tartarus.org/~simon-git/gitweb/?p=putty.git;a=commitdiff;h=bc6c15ab5f636e05b7e91883f0031a7e06117947 https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-2563 Description: Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816921 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_putty: upstream: http://tartarus.org/~simon-git/gitweb/?p=putty.git;a=commitdiff;h=bc6c15ab5f636e05b7e91883f0031a7e06117947 upstream_putty: released (0.67-1) precise_putty: ignored (reached end-of-life) precise/esm_putty: DNE (precise was needs-triage) trusty_putty: ignored (reached end-of-life) trusty/esm_putty: DNE (trusty was needed) vivid/stable-phone-overlay_putty: DNE vivid/ubuntu-core_putty: DNE wily_putty: ignored (reached end-of-life) xenial_putty: not-affected (0.67-1) yakkety_putty: not-affected (0.67-1) zesty_putty: not-affected (0.67-1) artful_putty: not-affected (0.67-1) bionic_putty: not-affected (0.67-1) cosmic_putty: not-affected (0.67-1) disco_putty: not-affected (0.67-1) devel_putty: not-affected (0.67-1)