CVE-2024-31497

NameCVE-2024-31497
DescriptionIn PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3839-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
filezilla (PTS)bullseye3.52.2-3+deb11u1vulnerable
bookworm3.63.0-1+deb12u3vulnerable
trixie3.68.1-1fixed
forky, sid3.69.6-2fixed
putty (PTS)bullseye0.74-1+deb11u2fixed
bullseye (security)0.74-1+deb11u1vulnerable
bookworm0.78-2+deb12u2fixed
bookworm (security)0.78-2+deb12u1vulnerable
forky, sid, trixie0.83-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
filezillasource(unstable)3.67.0-1
puttysourcebuster0.74-1+deb11u1~deb10u2DLA-3839-1
puttysourcebullseye0.74-1+deb11u2
puttysourcebookworm0.78-2+deb12u2
puttysource(unstable)0.81-1

Notes

[bookworm] - filezilla <no-dsa> (Minor issue)
[bullseye] - filezilla <no-dsa> (Minor issue)
[buster] - filezilla <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2024/04/15/6
https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
Fixed by: https://git.tartarus.org/?p=simon/putty.git;a=commitdiff;h=c193fe9848f50a88a4089aac647fecc31ae96d27 (0.81)

Search for package or bug name: Reporting problems