Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execution via a crafted DSA signature, which is not properly handled when performing certain bit-shifting operations during modular multiplication.
Cite this page
CVE-2013-4206. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2013-4206
Use CWE-119, Putty vendor hub and Putty product page to widen CVE-2013-4206 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-17067, CVE-2019-9898 and CVE-2021-36367 for nearby disclosures in the same product family.