Advertisement
Top

Security flaw in top SSH client could let hackers recover cryptographic private keys

April 17, 2024

Via: TechRadar
Category:
Multiple versions of the PuTTY SSH client were found to be vulnerable to a high-severity flaw which allowed, in certain scenarios, threat actors to exfiltrate private keys used to generate cryptographic signatures.

As a result, the attackers could gain unauthorized access to SSH servers, or could be allowed to sign commits as a developer.

As reported by BleepingComputer, the vulnerability in versions PuTTY versions 0.68 to 0.80 is tracked as CVE-2024-31497, and affects at least these software:

Read More on TechRadar