












<p>We've released <a href="https://hachyderm.io/tags/PuTTY" class="mention hashtag" rel="tag">#<span>PuTTY</span></a> version 0.85.</p><p>This release fixes five security vulnerabilities. None is _known_ to be severe, but at least one of them could be.</p><p>The potentially severe ones:</p><p>• Pageant could use freed memory if one of its clients deletes an encrypted private key while the user is still answering a passphrase prompt triggered by another client's attempt to use the key. If this was triggered via a malicious user with access to agent forwarding, they might also have had some control over the contents of the reused memory.</p><p>• The OpenSSH encrypt-then-MAC cipher modes (but not the ones PuTTY uses by default) had a buffer overflow if a server sent the largest permitted packet size.</p>
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。