UbuntuUpdates.org

Package "putty"

Name: putty

Description:

Telnet/SSH client for X

Latest version: 0.63-4ubuntu0.1
Release: trusty (14.04)
Level: updates
Repository: universe

Links


Download "putty"


Other versions of "putty" in Trusty

Repository Area Version
base universe 0.63-4
security universe 0.63-4ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.63-4ubuntu0.1 2015-06-23 14:06:25 UTC

  putty (0.63-4ubuntu0.1) trusty-security; urgency=medium

  * SECURITY UPDATE: PuTTY did not properly wipe SSH-2 Private Keys from
    system memory, which can allow local users to obtain sensitive information
    by reading the memory. (LP: #1467631)
    - debian/patches/private-key-not-wiped-2.patch: Add in fix patch from
      Debian 0.63-10 packaging. Thanks to Patrick Coleman for the original
      patch.
    - CVE-2015-2157

 -- Thomas Ward <email address hidden> Mon, 22 Jun 2015 14:07:28 -0400

1467631 CVE-2015-2157 - SSH2 Private Keys Not Properly Wiped from Memory
CVE-2015-2157 The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which a



About   -   Send Feedback to @ubuntu_updates