Key management errors in PuTTY - CVE-2019-9894
Published: March 21, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31143
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9894
CWE-ID: CWE-320
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
Affected software
PuTTY
putty (Alpine package)
putty
Fedora
putty (Alpine package)
putty
Fedora
How to mitigate CVE-2019-9894
Install update from vendor's website.
PuTTY - update to 0.71
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36LWQ3NPFIV7DC7TC4KFPRYRH2OR7SZ2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LDO3F267P347E6U2IILFCYW7JPTLCCES/
- https://seclists.org/bugtraq/2019/Apr/6
- https://security.netapp.com/advisory/ntap-20190404-0001/
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://www.debian.org/security/2019/dsa-4423