Zum Inhalt springen

PuTTY Release Notes

1 Eintrag aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

PuTTY

PuTTY 0.85 behebt mehrere Sicherheitslücken

PuTTY 0.85 behebt mehrere Sicherheitslücken, darunter einen aus der Ferne auslösbaren Use-after-free in Pageant, Pufferüberläufe bei OpenSSH-Encrypt-then-MAC-Cipher-Modes und bei der Entschlüsselung manipulierter privater Schlüssel sowie Denial-of-Service-Probleme durch eine Endlosschleife und unbegrenzten Speicherverbrauch.

  • Security issue: fixed a remotely triggerable use-after-free in Pageant. (Might be exploitable to execute code, although this is not proved.)
  • Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. (However they are only used if a server supports nothing else.)
  • Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. (Only triggerable on purpose if you let somebody else generate your key for you.)
  • Denial-of-service security fixes: a server can trigger a tight loop in PuTTY, and even a MITM can make it consume unlimited memory at startup.

Originalquelle(öffnet in neuem Tab)Problem melden