Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
PuTTY 0.85 behebt mehrere Sicherheitslücken
PuTTY 0.85 behebt mehrere Sicherheitslücken, darunter einen aus der Ferne auslösbaren Use-after-free in Pageant, Pufferüberläufe bei OpenSSH-Encrypt-then-MAC-Cipher-Modes und bei der Entschlüsselung manipulierter privater Schlüssel sowie Denial-of-Service-Probleme durch eine Endlosschleife und unbegrenzten Speicherverbrauch.
- Security issue: fixed a remotely triggerable use-after-free in Pageant. (Might be exploitable to execute code, although this is not proved.)
- Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. (However they are only used if a server supports nothing else.)
- Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. (Only triggerable on purpose if you let somebody else generate your key for you.)
- Denial-of-service security fixes: a server can trigger a tight loop in PuTTY, and even a MITM can make it consume unlimited memory at startup.