Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2019.0153
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2019-0153)
Summary:The remote host is missing an update for the 'filezilla, libfilezilla, putty, wxgtk' package(s) announced via the MGASA-2019-0153 advisory.
Description:Summary:
The remote host is missing an update for the 'filezilla, libfilezilla, putty, wxgtk' package(s) announced via the MGASA-2019-0153 advisory.

Vulnerability Insight:
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before
0.71 can occur before host key verification (CVE-2019-9894).

In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer
overflow exists in any kind of server-to-client forwarding (CVE-2019-9895).

Multiple denial-of-service attacks that can be triggered by writing to the
terminal exist in PuTTY versions before 0.71 (CVE-2019-9897).

Potential recycling of random numbers used in cryptography exists within
PuTTY before 0.71 (CVE-2019-9898).

The putty package has been updated to version 0.71 and the filezilla package
has been updated and patched to fix these issues.

wxgtk has been updated to fix an assert when starting filezilla.

Affected Software/OS:
'filezilla, libfilezilla, putty, wxgtk' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-9894
Bugtraq: 20190403 [SECURITY] [DSA 4423-1] putty security update (Google Search)
https://seclists.org/bugtraq/2019/Apr/6
Debian Security Information: DSA-4423 (Google Search)
https://www.debian.org/security/2019/dsa-4423
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LDO3F267P347E6U2IILFCYW7JPTLCCES/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36LWQ3NPFIV7DC7TC4KFPRYRH2OR7SZ2/
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
https://lists.debian.org/debian-lts-announce/2019/04/msg00023.html
SuSE Security Announcement: openSUSE-SU-2019:1113 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00004.html
SuSE Security Announcement: openSUSE-SU-2019:1123 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00020.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-9895
Common Vulnerability Exposure (CVE) ID: CVE-2019-9897
Common Vulnerability Exposure (CVE) ID: CVE-2019-9898
BugTraq ID: 107523
http://www.securityfocus.com/bid/107523
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.