Loading
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
Cite this page
CVE-2015-2157. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2015-2157
Use CWE-200, Debian vendor hub and Debian Linux product page to widen CVE-2015-2157 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-68670, CVE-2025-62600 and CVE-2025-62599 for nearby disclosures in the same product family.