PuTTY: Pre-authentication buffer overflow. Posted on Friday, October 29, 2004 @ 02:49:11 AST
Topic: advisories
|
 PuTTY 0.56, released today, fixes a serious security hole which can allow a server to execute code of its choice on a PuTTY client connecting to it. In SSH2, the attack can be performed before host key verification, meaning that even if you trust the server you think you are connecting to, a different machine could be impersonating it and could launch the attack before you could tell the difference. We recommend everybody upgrade to 0.56 as soon as possible.
compelet story |
|
| PuTTY: Pre-authentication buffer overflow. | Login/Create an Account | 0 comments | | | The comments are owned by the poster. We aren't responsible for their content. |
|
|
| |
| Article Rating | Average Score: 4 Votes: 1

| |
|