Insufficient verification of data authenticity in PuTTY - CVE-2021-36367
Published: July 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient verification of data source when processing authentication responses. A remote attacker can send a spoofed authentication prompt even after an SSH session has been established with the original server and trick the victim into providing authentication credentials.
Affected software
Arch Linux
Debian Linux
Fedora
putty (Debian package)
putty
How to mitigate CVE-2021-36367
putty (Debian package) - addressed in versions 0.74-1+deb11u1, 0.78-2+deb12u1
putty - addressed in versions 0.76-1.el7, 0.76-1.el8