Candidate: CVE-2017-6542 PublicDate: 2017-03-27 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6542 http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-agent-fwd-overflow.html https://git.tartarus.org/?p=simon/putty.git;a=commitdiff;h=4ff22863d895cb7ebfced4cf923a012a614adaa8 Description: The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=857642 Priority: medium Discovered-by: Tim Kosse Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_putty: upstream_putty: released (0.67-3) precise_putty: ignored (reached end-of-life) precise/esm_putty: DNE (precise was needed) trusty_putty: ignored (reached end-of-life) trusty/esm_putty: DNE (trusty was needed) vivid/stable-phone-overlay_putty: DNE vivid/ubuntu-core_putty: DNE xenial_putty: released (0.67-3build0.16.04.1) yakkety_putty: ignored (reached end-of-life) zesty_putty: ignored (reached end-of-life) artful_putty: ignored (reached end-of-life) bionic_putty: not-affected (0.70-4) cosmic_putty: not-affected (0.70-4) disco_putty: not-affected (0.70-4) devel_putty: not-affected (0.70-4)