"This release fixes the following security issues: - In some situations an SSH server could cause PuTTY to access freed mdmory by pretending to accept an SSH key and then refusing the actual signature. It can only happen if you're using an SSH agent. - New configuration option to disable PuTTY's default policy of changing its host key algorithm preferences to prefer keys it already knows. (There is a theoretical information leak in this policy.)"
https://www.chiark.greenend.org.uk/~sgtatham/putty/ has not been updated yet, but points to https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html which has been updated recently.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4e7ecac90eb040035abf08ad4f1964893ded0a81 commit 4e7ecac90eb040035abf08ad4f1964893ded0a81 Author: Jeroen Roovers <jer@gentoo.org> AuthorDate: 2020-06-28 06:58:57 +0000 Commit: Jeroen Roovers <jer@gentoo.org> CommitDate: 2020-06-28 06:59:59 +0000 net-misc/putty: Version 0.74 Package-Manager: Portage-2.3.103, Repoman-2.3.23 Bug: https://bugs.gentoo.org/729860 Signed-off-by: Jeroen Roovers <jer@gentoo.org> net-misc/putty/Manifest | 1 + net-misc/putty/putty-0.74.ebuild | 86 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 87 insertions(+)
Let us know when ready to stable.
(In reply to Sam James from comment #3) > Let us know when ready to stable. Any objections, or we'll proceed?
ppc stable
ppc64 stable
x86 stable
amd64 stable
sparc stable
hppa stable
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6bdbfce3078602797134046834a6e14f4b3beec1 commit 6bdbfce3078602797134046834a6e14f4b3beec1 Author: Jeroen Roovers <jer@gentoo.org> AuthorDate: 2020-07-23 09:03:27 +0000 Commit: Jeroen Roovers <jer@gentoo.org> CommitDate: 2020-07-23 09:05:41 +0000 net-misc/putty: Old Package-Manager: Portage-3.0.0, Repoman-2.3.23 Bug: https://bugs.gentoo.org/729860 Signed-off-by: Jeroen Roovers <jer@gentoo.org> net-misc/putty/Manifest | 1 - net-misc/putty/putty-0.73.ebuild | 86 ---------------------------------------- 2 files changed, 87 deletions(-)
commit 763b2a4f89e58d6a467b0771f39944510fa753c3 Author: Rolf Eike Beer <eike@sf-mail.de> Date: Thu Jul 23 08:55:58 2020 +0200 net-misc/putty: stable 0.74 for hppa, bug #729860
GLSA vote: no. Closing.