PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files.
http://secunia.com/advisories/24381
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=400804
Source: Mitre, NVD
Published: 2007-03-07
Updated: 2026-06-16
Base Score: 1.9
Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N
Severity: Low
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity: Medium
EPSS: 0.00037