The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


PuTTY SSH client vulnerability


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Tue, 26 Oct 2004 23:02:22 -0400
From: Anatole Shaw <[email protected]>
To: [email protected]
Subject: PuTTY SSH client vulnerability

>From http://www.chiark.greenend.org.uk/~sgtatham/putty/


2004-10-26 ANOTHER SECURITY HOLE, fixed in PuTTY 0.56 PuTTY 0.56, released today, fixes a serious security hole which can allow a server to execute code of its choice on a PuTTY client connecting to it. In SSH2, the attack can be performed before host key verification, meaning that even if you trust the server you think you are connecting to, a different machine could be impersonating it and could launch the attack before you could tell the difference. We recommend everybody upgrade to 0.56 as soon as possible. That's two really bad holes in three months. I'd like to apologise to all our users for the inconvenience.

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру