summary: Use-after-free bug when processing SSH-1 disconnect message
class: bug: This is clearly an actual problem we want fixed.
difficulty: fun: Just needs tuits, and not many of them.
priority: high: This should be fixed in the next release.
present-in: 0.72
fixed-in: 0.73 69201ad8936fe0ff1b8723b7a43accb5e9f1c888

If an SSH-1 server sends PuTTY a disconnection message (that is, message type 1, SSH_MSG_DISCONNECT), PuTTY would access an already-freed pointer to a linked list of packets in the course of handling it.

We don't know if this memory fault had any exploitable security impact. It has been assigned CVE-2019-17069. It is fixed in 0.73.

