CVE-2015-2157

low
Published 2015-03-27 · Modified 2026-05-06
CVSS v3
VIR risk
2.1

Description

The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
suse suse13.1affected
suse suse13.2affected
debian debian7.0affected
fedora fedora20affected
fedora fedora22affected
debian debianbookwormfixed0.63-10
debian debianbullseyefixed0.63-10
debian debianforkyfixed0.63-10
debian debiansidfixed0.63-10
debian debiantrixiefixed0.63-10

Application impact

VendorProductVersionsFixed
puttyputty0.51
puttyputty0.52
puttyputty0.53b
puttyputty0.54
puttyputty0.55
puttyputty0.56
puttyputty0.57
puttyputty0.58
puttyputty0.59
puttyputty0.60
puttyputty0.61
puttyputty0.62
puttyputty0.63
simon_tathamputty0.53

References

CWEs

CWE-200

💬 Discuss CVE-2015-2157 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.