MGASA-2020-0003

Advisory lineage Upstream: 2 Downstream: 0
Published: 05 Jan 2020, 15:37
Last modified:16 Apr 2026, 04:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jan 2020, 15:37
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated

Description

Updated putty packages fix security vulnerabilities Updated putty package fixes security vulnerabilities: Two separate vulnerabilities affecting the obsolete SSH-1 protocol, both available before host key checking. Vulnerability in all the SSH client tools (PuTTY, Plink, PSFTP, and PSCP) if a malicious program can impersonate Pageant. Crash in GSSAPI / Kerberos key exchange triggered if the server provided an ordinary SSH host key as part of the exchange. Insufficient handling of terminal escape sequences, that should delimit the pasted data in bracketed paste mode (CVE-2019-17068). Possible information leak caused by SSH-1 disconnection messages (CVE-2019-17069). The putty package has been updated to version 0.73, fixing theese issues and other bugs.

Affected Systems

  • mageiaputty

    < 0.73-1.mga7

References (5)