[GLSA-202407-11] PuTTY: Multiple Vulnerabilities

Severity High
Affected Packages 1
Unaffected Packages 1
CVEs 2

Multiple vulnerabilities have been discovered in PuTTY, the worst of which could lead to compromised keys.

Background
PuTTY is a free implementation of Telnet and SSH for Windows and Unix platforms, along with an xterm terminal emulator.

Description
Multiple vulnerabilities have been discovered in PuTTY. Please review the CVE identifiers referenced below for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All PuTTY users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/putty-0.81"

In addition, any keys generated with PuTTY versions 0.68 to 0.80 should be considered breached and should be regenerated.

Package Affected Version
pkg:ebuild/net-misc/putty?distro=gentoo < 0.81
Package Unaffected Version
pkg:ebuild/net-misc/putty?distro=gentoo >= 0.81
ID
GLSA-202407-11
Severity
high
URL
https://security.gentoo.org/glsa/202407-11
Published
2024-07-05T00:00:00
(2 months ago)
Modified
2024-07-05T00:00:00
(2 months ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2023-48795 CVE-2023-48795 https://nvd.nist.gov/vuln/detail/CVE-2023-48795
CVE CVE-2024-31497 CVE-2024-31497 https://nvd.nist.gov/vuln/detail/CVE-2024-31497
Bugzilla 920304 Bugzilla #920304 https://bugs.gentoo.org/show_bug.cgi?id=920304
Bugzilla 930082 Bugzilla #930082 https://bugs.gentoo.org/show_bug.cgi?id=930082
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/net-misc/putty?distro=gentoo net-misc putty < 0.81 gentoo
Unaffected pkg:ebuild/net-misc/putty?distro=gentoo net-misc putty >= 0.81 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...