Widely-Used PuTTY SSH Client Found Vulnerable to Key Recovery Attack
ID: c90b4125-3f65-5f7b-b40c-634df76b40e6
STIX ID: report--c90b4125-3f65-5f7b-b40c-634df76b40e6
Feed Name: The Hacker News
Threat Score
**Executive summary:** A critical vulnerability (CVE-2024-31497) in PuTTY versions 0.68–0.80 and several products that embed it causes biased ECDSA nonces for NIST P-521 keys, enabling full private-key recovery from roughly 60 signatures; maintainers have released patches (PuTTY 0.81, FileZilla 3.67.0, WinSCP 6.3.3, etc.) and recommend revoking affected keys and switching to RFC 6979-derived nonces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
