Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE: 2019:2017-1 Moderate: PuTTY SSH Protocol Security Fix

opensuse
Calendar Grey August 26, 2019
Dist Opensuse Esm H88
This patch for putty introduces significant security enhancements targeting vulnerabilities in the SSH protocol within openSUSE.
An update that contains security fixes can now be installed.

Description

This update for putty fixes the following issues:

Update to new upstream release 0.72 [boo#1144547, boo#1144548]

* Fixed two separate vulnerabilities affecting the obsolete SSH-1

protocol, both available before host key checking.

* Fixed a vulnerability in all the SSH client tools (PuTTY, Plink, PSFTP

and PSCP) if a malicious program can impersonate Pageant.

* Fixed a crash in GSSAPI / Kerberos key exchange triggered if the server

provided an ordinary SSH host key as part of the exchange.

This update was imported from the openSUSE:Leap:15.0:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-2017=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2019-2017=1

Package List

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

putty-0.72-bp151.4.3.1

putty-debuginfo-0.72-bp151.4.3.1

putty-debugsource-0.72-bp151.4.3.1

- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):

putty-0.72-bp150.4.9.1

References

https://bugzilla.suse.com/1144547

https://bugzilla.suse.com/1144548

--

Announcement ID: openSUSE-SU-2019:2017-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here