CVE-2015-2157

Publication date 27 March 2015

Last updated 24 July 2024


Ubuntu priority

Description

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

Status

Package Ubuntu Release Status
putty 17.04 zesty
Not affected
16.10 yakkety
Not affected
16.04 LTS xenial
Not affected
15.10 wily
Not affected
15.04 vivid
Not affected
14.10 utopic
Fixed 0.63-8ubuntu0.1
14.04 LTS trusty
Fixed 0.63-4ubuntu0.1
12.04 LTS precise Ignored end of life
10.04 LTS lucid Ignored end of life