Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on Vulnerability in PuTTY in the Shared & Semi-Dedicated forum
Just got this through the NTBugTraq mailing list. Title: Vulnerabilities in PuTTY and PSCP *Vulnerability Description:* PuTTY is a free implementation of Telnet and SSH ...

  1. #1
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003

    Vulnerability in PuTTY

    Just got this through the NTBugTraq mailing list.

    Title: Vulnerabilities in PuTTY and PSCP

    *Vulnerability Description:*

    PuTTY is a free implementation of Telnet and SSH for Win32 and Unix platforms, along with an xterm terminal emulator.

    PuTTY and PSCP are client applications used by network and security administrators to login securily to networked server systems.

    We have found that by sending specially crafted packets to the client during the authentication process, an attacker is able to compromise and execute arbitrary code on the machine running PuTTY or PSCP.

    In SSH2, an attacker impersonating a trusted host can launch an attack before the client has the ability to determine the difference between the trusted and fake host. This attack is performed before host key verification.

    *Vulnerable Packages:*

    PuTTY 0.54 and previous versions are vulnerable.


    *Solution/Vendor Information/Workaround:*

    PuTTY 0.55 fixes these vulnerabilities. It is available at: http://www.chiark.greenend.org.uk/~s.../download.html

    PuTTY maintainers recommend that everybody upgrade to 0.55 as soon as possible.
    The full advisory can be viewed at http://www.coresecurity.com/common/s...&idxseccion=10
    if anyone's interested.

    Also keep in mind that programs that make use of the PuTTY engine (such as WinSCP) may also be vulnerable.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  2. #2
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    Just to confirm, there is an upgrade for WinSCP that uses the new PuTTY core. Be sure to upgrae that, too.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  3. #3
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,648
    Hi Jason,

    Thanks for the update. I meant to say something shortly after you posted this. Then got involved in other stuff.

    I don't use putty but I downloaded the WinSCP update. The update solved another problem I was having after the previous update.

    Really surprised that you caught the WinSCP update rather than Vin. He is the WinSCP champion so to speak.

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  4. #4
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    Connie,

    The only reason I noticed is because there was an email sent out by someone on our support staff at work warning of the PuTTY vulnerability. Knowing that many people here use PuTTY (and its derivitives), I figured I'd pass the warning on. When I did my own upgrade I decided to check out WinSCP since I know that is based on PuTTY, and sure enough, there was an update for that as well.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Yep, I should have mentioned that upgrade, but jason beat me to it...

    I've been moving programs to my striped SATA drives, as I upgrade them, and WoW, what a difference!

    One thing I wanted to mention - yes, WinSCP is built on PuTTY, but not only that - you can use PuTTY from a window inside WinSCP, so it's kind of a circular thing, if you know what I mean.

    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    While we're talking about upgrades, I don't know if anyone on JagPC, but me, runs the Kiwi Syslog Daemon. Most of the ppl here don't even know what a 'system log' is. In case you do, they just came out with a new 'stable' (non-beta) version - 7.1.4.

    http://www.kiwisyslog.com/

    Been using it for a couple of years. Highly recommended!
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •