Loading
The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow local users to discover private RSA and DSA keys.
Use CWE-200, Putty vendor hub and Putty product page to widen CVE-2013-4208 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-17067, CVE-2019-9898 and CVE-2021-36367 for nearby disclosures in the same product family.