Bugzilla – Bug 1022772
VUL-0: CVE-2016-6167: putty: Multiple untrusted search path vulnerabilities
Last modified: 2017-01-31 10:16:35 UTC
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current working directory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6167 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-6167.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6167 https://packetstormsecurity.com/files/137742/Putty-Beta-0.67-DLL-Hijacking.html http://www.securityfocus.com/archive/1/archive/1/538848/100/0/threaded
Windows only.