Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1440
CVE-2004-1440
Description
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute arbitrary code via an SSH2 packet with a base argument that is larger than the mod argument, which causes the modpow function to write memory before the beginning of its buffer, and (2) remote malicious servers to cause a denial of service (client crash) and possibly execute arbitrary code via a large bignum during authentication.
Affected products
8cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:putty:putty:0.48:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.49:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.50:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.51:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.52:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.53:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.53b:*:*:*:*:*:*:*
- cpe:2.3:a:putty:putty:0.54:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/12212/nvdPatch
- www.gentoo.org/security/en/glsa/glsa-200408-04.xmlnvdPatch
- www.securityfocus.com/bid/10850nvdPatch
- marc.infonvd
- www.chiark.greenend.org.uk/~sgtatham/putty/changes.htmlnvd
- www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-modpow.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16885nvd
News mentions
0No linked articles in our index yet.