Use of a broken or risky cryptographic algorithm in PuTTY - CVE-2019-9898
Published: March 21, 2019 / Updated: July 17, 2020
Vulnerability identifier: #VU31145
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9898
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Affected software
PuTTY
putty (Alpine package)
putty
Fedora
putty (Alpine package)
putty
Fedora
How to mitigate CVE-2019-9898
Install update from vendor's website.
PuTTY - update to 0.71
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html
- http://www.securityfocus.com/bid/107523
- https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36LWQ3NPFIV7DC7TC4KFPRYRH2OR7SZ2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LDO3F267P347E6U2IILFCYW7JPTLCCES/
- https://seclists.org/bugtraq/2019/Apr/6
- https://security.netapp.com/advisory/ntap-20190329-0002/
- https://security.netapp.com/advisory/ntap-20190401-0002/
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://www.debian.org/security/2019/dsa-4423