NewsSecurity Vulnerabilities

PuTTY Releases Security Update (0.71)

PuTTY have released a security update to address multiple vulnerabilities in the PuTTYSSH client. A remote unauthenticated attacker could exploit some or all of these vulnerabilities to extract sensitiveness information, take control of a PuTTY session or cause a local denial-of-service condition.

Affected versions : PuTTY – Versions prior to 0.71

The latest version of PuTTY is 0.71 and was released on 16-03-2019.

Changes in version 0.71

Security fixes found by an EU-funded bug bounty programme:

a remotely triggerable memory overwrite in RSA key exchange, which can occur before host key verification

potential recycling of random numbers used in cryptography

on Windows, hijacking by a malicious help file in the same directory as the executable

on Unix, remotely triggerable buffer overflow in any kind of server-to-client forwarding

multiple denial-of-service attacks that can be triggered by writing to the terminal

Other security enhancements: major rewrite of the crypto code to remove cache and timing side channels.

User interface changes to protect against fake authentication prompts from a malicious server.

We now provide pre-built binaries for Windows on Arm.

Hardware-accelerated versions of the most common cryptographic primitives: AES, SHA-256, SHA-1.

GTK PuTTY now supports non-X11 displays (e.g. Wayland) and high-DPI configurations.

Type-ahead now works as soon as a PuTTY window is opened: keystrokes typed before authentication has finished will be buffered instead of being dropped.

Support for GSSAPI key exchange: an alternative to the older GSSAPI authentication system which can keep your forwarded Kerberos credentials updated during a long session.

More choices of user interface for clipboard handling.

New terminal features: support the REP escape sequence (fixing an ncurses screen redraw failure), true colour, and SGR 2 dim text.

Pressing Ctrl+Shift+PgUp or Ctrl+Shift+PgDn now takes you straight to the top or bottom of the terminal scrollback.

Update

Downloaded the latest update here

Details on how to update PuTTY can be found here.

Duncan

Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.