[Bug 297593] security/putty*: security update to 0.85

[email protected]
Newsgroups gmane.os.freebsd.devel.ports.bugs
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297593

            Bug ID: 297593
           Summary: security/putty*: security update to 0.85
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://www.chiark.greenend.org.uk/~sgtatham/putty/cha
                    nges.html
                OS: Any
            Status: New
          Keywords: patch-ready, security
          Severity: Affects Only Me
          Priority: ---
         Component: Individual Port(s)
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected], [email protected],
                    [email protected]
             Flags: maintainer-feedback+, merge-quarterly?

Please merge https://github.com/freebsd/freebsd-ports/pull/587 to obtain
security fixes.

Please MFH.

---------------------------------------------------
<https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html> contains:

 These features are new in 0.85 (released 2026-08-16):

    Security issue: fixed a remotely triggerable use-after-free in Pageant.
(Might be exploitable to execute code, although this is not proved.)
    Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH
encrypt-then-MAC cipher modes are in use. (However they are only used if a
server supports nothing else.)
    Security issue: fixed a buffer overflow in private key decryption, if the
private key is constructed maliciously. (Only triggerable on purpose if you let
somebody else generate your key for you.)
    Denial-of-service security fixes: a server can trigger a tight loop in
PuTTY, and even a MITM can make it consume unlimited memory at startup.

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.