[Bug 297593] security/putty*: security update to 0.85
| Newsgroups | gmane.os.freebsd.devel.ports.bugs |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297593
Bug ID: 297593
Summary: security/putty*: security update to 0.85
Product: Ports & Packages
Version: Latest
Hardware: Any
URL: https://www.chiark.greenend.org.uk/~sgtatham/putty/cha
nges.html
OS: Any
Status: New
Keywords: patch-ready, security
Severity: Affects Only Me
Priority: ---
Component: Individual Port(s)
Assignee: [email protected]
Reporter: [email protected]
CC: [email protected], [email protected],
[email protected]
Flags: maintainer-feedback+, merge-quarterly?
Please merge https://github.com/freebsd/freebsd-ports/pull/587 to obtain
security fixes.
Please MFH.
---------------------------------------------------
<https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html> contains:
These features are new in 0.85 (released 2026-08-16):
Security issue: fixed a remotely triggerable use-after-free in Pageant.
(Might be exploitable to execute code, although this is not proved.)
Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH
encrypt-then-MAC cipher modes are in use. (However they are only used if a
server supports nothing else.)
Security issue: fixed a buffer overflow in private key decryption, if the
private key is constructed maliciously. (Only triggerable on purpose if you let
somebody else generate your key for you.)
Denial-of-service security fixes: a server can trigger a tight loop in
PuTTY, and even a MITM can make it consume unlimited memory at startup.
--
You are receiving this mail because:
You are the assignee for the bug.