Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 2024:0005-1 critical: putty vulnerability exposure alert

opensuse
Calendar Grey January 3, 2024
Dist Opensuse Esm H88
A critical update for PuTTY has been released for CVE-2023-48795, providing essential security fixes for openSUSE users.
An update that fixes one vulnerability is now available

Description

This update for putty fixes the following issues:

putty was updated to to release 0.80:

* Fix CVE-2023-48795 [boo#1218128]

- Update to release 0.79

* Terminal mouse tracking: support for mouse movements which are not

drags, and support for horizontal scroll events (e.g. generated by

trackpads).

* Fixed: PuTTY could fail an assertion if a resize control sequence was

sent by the server while the window was docked to

one half of the screen in KDE.

* Fixed: PuTTY could fail an assertion if you tried to change the font

size while the window was maximised.

- Update to release 0.78

* Support for OpenSSH certificates, for both user authentication keys

and host keys.

* New SSH proxy modes, for running a custom shell command or subsystem

on the proxy server instead of forwarding a port through it.

* New plugin system to allow a helper program to provide responses in

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2024-5=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

putty-0.80-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2023-48795.html

https://bugzilla.suse.com/1218128

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0005-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here