PuTTY 0.71 released, fixing security vulnerabilities
chiark.greenend.org.uk
chiark.greenend.org.uk
Most major seems to be this: A malicious server could trigger a buffer overrun by abusing the RSA key exchange protocol. This would happen before host key verification, so even if you trust the server you intended to connect to, you would still be at risk.
https://community.arm.com/developer/tools-software/tools/b/t...
Disabling the stack protector is a pretty big "wrinkle" in my opinion.
PuTTY 0.71: WoA
$ strings putty.exe | grep Compiler:
%sCompiler: clang %sSide thought: why doesn’t Putty follow a more normal setup and configuration process, i.e. why does it have its own private key format and tooling around that instead of using standards?
See eg https://latacora.singles/2018/08/03/the-default-openssh.html (which is from 2018, but I think the weakness has been well known for a long time).
Putty is ancient. It was perfectly normal c.1999.
Just checked Windows 10 1803 and it appears to be installed by default on my work Windows machine. Nice!
Having a ~/.ssh/config file has been a lot easier to work with than PuTTY's list box of hosts, and I can share my config across my Linux & Mac boxes.
For serial port connections, PuTTY is fantastic. Thank you Simon!
Then again I'm not dealing with anything mission critical, so it not being open source doesn't bother me too much.