PuTTY vulnerability allows attackers to uncover private keys

Daniel Puchert

Journalist
Staff member
Joined
Mar 6, 2024
Messages
3,336
Reaction score
3,247
PuTTY vulnerability allows attackers to uncover private keys

A vulnerability within PuTTY version 0.68 through 0.80 allows attackers to recover a user’s private key using at least 60 digital signatures that use the Elliptic Curve Digital Signature Algorithm (ECDSA).

Researchers from Ruhr University Bochum, Fabian Baumer and Marcus Brinkman, first discovered the vulnerability, which is tracked as CVE-2024-31497.
 
Top
Sign up to the MyBroadband newsletter
X