SSH client PuTTY 0.63 plugs security holes
Summary
In August 2013 PuTTY 0.63 closed four holes rated as critical in the SSH client widely used on Windows. They affected the modmul function, the handling of public key signatures, buffer overflows when checking DSA signatures, and the wiping of session keys and passphrases from memory. Since PuTTY had not been updated since 2011 and has no update function, users had to act themselves.
Ideas
- Bugs in cryptographic arithmetic can endanger signatures and keys.
- Secrets must be reliably wiped from memory after use.
- Software without auto-update often stays on old versions for years.
Insights
- Missing update mechanisms shift responsibility for security entirely to users.
- Even small, proven tools need regular security maintenance.
Facts
- The previous PuTTY version dated from 2011.
- Developer Simon Tatham recommended updating immediately.
References
Critique
- The report does not say whether the holes could be exploited before logging in to the server.
Recommendations
- Manage tools without auto-update through software distribution or a package manager.
- On Windows, use the built-in OpenSSH client if you do not need PuTTY’s range of features.
Links to the original source and the Web Archive open in a new tab.