Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 729860 - <net-misc/putty-0.74: Out of bounds read when using an SSH agent
Summary: <net-misc/putty-0.74: Out of bounds read when using an SSH agent
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://lists.tartarus.org/pipermail/...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-27 13:55 UTC by Sam James
Modified: 2020-07-26 05:12 UTC (History)
1 user (show)

See Also:
Package list:
net-misc/putty-0.74
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-27 13:55:58 UTC
"This release fixes the following security issues:

 - In some situations an SSH server could cause PuTTY to access freed
   mdmory by pretending to accept an SSH key and then refusing the
   actual signature. It can only happen if you're using an SSH agent.

 - New configuration option to disable PuTTY's default policy of
   changing its host key algorithm preferences to prefer keys it
   already knows. (There is a theoretical information leak in this
   policy.)"
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2020-06-28 06:57:43 UTC
https://www.chiark.greenend.org.uk/~sgtatham/putty/ has not been updated yet, but points to https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html which has been updated recently.
Comment 2 Larry the Git Cow gentoo-dev 2020-06-28 07:00:05 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4e7ecac90eb040035abf08ad4f1964893ded0a81

commit 4e7ecac90eb040035abf08ad4f1964893ded0a81
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-06-28 06:58:57 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-06-28 06:59:59 +0000

    net-misc/putty: Version 0.74
    
    Package-Manager: Portage-2.3.103, Repoman-2.3.23
    Bug: https://bugs.gentoo.org/729860
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-misc/putty/Manifest          |  1 +
 net-misc/putty/putty-0.74.ebuild | 86 ++++++++++++++++++++++++++++++++++++++++
 2 files changed, 87 insertions(+)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-28 13:24:07 UTC
Let us know when ready to stable.
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-14 17:10:16 UTC
(In reply to Sam James from comment #3)
> Let us know when ready to stable.

Any objections, or we'll proceed?
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-16 23:49:54 UTC
ppc stable
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-17 00:08:02 UTC
ppc64 stable
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-17 23:28:06 UTC
x86 stable
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-17 23:28:20 UTC
amd64 stable
Comment 9 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-18 18:35:28 UTC
sparc stable
Comment 10 Rolf Eike Beer archtester 2020-07-22 15:33:19 UTC
hppa stable
Comment 11 Larry the Git Cow gentoo-dev 2020-07-23 09:05:45 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6bdbfce3078602797134046834a6e14f4b3beec1

commit 6bdbfce3078602797134046834a6e14f4b3beec1
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-07-23 09:03:27 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-07-23 09:05:41 +0000

    net-misc/putty: Old
    
    Package-Manager: Portage-3.0.0, Repoman-2.3.23
    Bug: https://bugs.gentoo.org/729860
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-misc/putty/Manifest          |  1 -
 net-misc/putty/putty-0.73.ebuild | 86 ----------------------------------------
 2 files changed, 87 deletions(-)
Comment 12 Sergei Trofimovich (RETIRED) gentoo-dev 2020-07-25 08:57:26 UTC
commit 763b2a4f89e58d6a467b0771f39944510fa753c3
Author: Rolf Eike Beer <eike@sf-mail.de>
Date:   Thu Jul 23 08:55:58 2020 +0200

    net-misc/putty: stable 0.74 for hppa, bug #729860
Comment 13 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-26 05:12:00 UTC
GLSA vote: no.

Closing.