« Protx DDoS attack |
Main
| US Dollar continues down »
November 05, 2004
PuTTY SSH client vulnerability
A PuTTY SSH client vulnerability was reported on Security Focus, apparently the second major security flaw in 3 months.
According to Anatole Shaw,
allow a server to execute code of its choice on a PuTTY client
connecting to it. In SSH2, the attack can be performed before host key verification, meaning that even if you trust the server you think you are connecting to, a different machine could be impersonating it and could launch the attack before you could tell the difference.
So if you missed that update while celebrating Hallowe'en, you may want to ensure you download PuTTY 0.56 now.
Posted by at November 5, 2004 02:20 PM
> Discuss this in the Platinax Business forums
|