Use of a broken or risky cryptographic algorithm in PuTTY - CVE-2019-9898

 

Use of a broken or risky cryptographic algorithm in PuTTY - CVE-2019-9898

Published: March 21, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31145
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9898
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.


Affected software

PuTTY
putty (Alpine package)
putty
Fedora

How to mitigate CVE-2019-9898

Install update from vendor's website.

PuTTY - update to 0.71
putty (Alpine package) - update to 0.71-r0
putty - addressed in versions 0.71-1.el7, 0.71-1.fc28, 0.71-1.fc29, 0.71-1.fc30

External References

Related Security Bulletins