Debian Security Advisory
DSA-4423-1 putty -- security update
- Date Reported:
- 03 Apr 2019
- Affected Packages:
- putty
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-9894, CVE-2019-9895, CVE-2019-9897, CVE-2019-9898.
- More information:
-
Multiple vulnerabilities were found in the PuTTY SSH client, which could result in denial of service and potentially the execution of arbitrary code. In addition, in some situations random numbers could potentially be re-used.
For the stable distribution (stretch), these problems have been fixed in version 0.67-3+deb9u1.
We recommend that you upgrade your putty packages.
For the detailed security status of putty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/putty