PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords by obtaining access to the process' memory.
| Software | From | Fixed in |
|---|---|---|
| putty / putty | 0.59 | 0.59.x |
| putty / putty | 0.60 | 0.60.x |
| putty / putty | 0.61 | 0.61.x |