Elektrine lite

← Feed

@simontatham@hachyderm.io

Post #1321970

2024-04-15 19:20 UTC

We've released #PuTTY version 0.81. This is a SECURITY UPDATE, fixing a #vulnerability in ECDSA signing for #SSH. If you've used a 521-bit ECDSA key (ecdsa-sha2-nistp521) with any previous version of PuTTY, consider it compromised! Generate a new key pair, and remove the old public key from authorized_keys files. Other key types are not affected, even other sizes of ECDSA. In particular, Ed25519 is fine. This vulnerability has id CVE-2024-31497. Full information is at https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html

Replies (9)

  • @cloud_manul@nrw.social 2024-04-15 20:04

    @simontatham Hi and thanks for the quick bugfix. From what I know, ecdsa-sha2-nistp521 has never been the default key type in Puttygen, so "normal" keys (mostly ssh-rsa and ssh-ed25519) should be fine?

    Open ##1544711

  • @Filene@dragon.style 2024-04-15 21:07

    @simontatham Thank you for your continued development of this application, it's essential and I've relied upon it. πŸ™‡β€β™€οΈπŸ™πŸ’–

    Open ##1544713

  • @jcuff@mastodon.mit.edu 2024-04-15 22:15

    @simontatham superb write up and repair. Y’all were making safe β€œk” before making safe β€œk” was cool. I’m just glad we have folks still around to know how computers work. Thanks team!!

    Open ##1544714

  • @virtuous_sloth@cosocial.ca 2024-04-15 22:22

    @simontatham Used such a key with PuTTY, or created such a key with PuTTY?

    Open ##1544715

  • @lispi314@udongein.xyz 2024-04-16 02:40

    @simontatham @indigoparadox If I understand from skimming the link, this solely affects PuTTY (on Windows) and /not/ other implementations of SSH, right?

    Open ##1544718

  • @kramse@social.kramse.org 2024-04-16 04:35

    @simontatham so sad to hear this news, but assured by the open information! Thanks for your long lasting and hard work on Putty and other projects.

    Open ##1544724

  • @brnrd@bsd.network 2024-04-16 10:49

    @simontatham Given that that's 3 additional clicks in the PuTTYgen UI (ECDSA, Dropdown, nistp521) I can almost assure we won't have any in our enterprise. Surprised to see that the default in PuTTYgen 0.81 is still RSA, and only 2048 bits. Ed25519 even works with RHEL 7 (EoL 2024-06-30).

    Open ##1544725

  • @lnr@tech.lgbt 2024-04-16 11:44

    @simontatham Also thanks for posting these here. It really helps spread the word!

    Open ##1544728

  • @anonymous236@hachyderm.io 2024-06-11 07:00

    @simontatham is ArcosPutty 75.1.8 vulnerable to CVE-2024-31497?

    Open ##1544729