![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.10.2020.0003 |
Category: | Mageia Linux Local Security Checks |
Title: | Mageia: Security Advisory (MGASA-2020-0003) |
Summary: | The remote host is missing an update for the 'putty' package(s) announced via the MGASA-2020-0003 advisory. |
Description: | Summary: The remote host is missing an update for the 'putty' package(s) announced via the MGASA-2020-0003 advisory. Vulnerability Insight: Updated putty package fixes security vulnerabilities: Two separate vulnerabilities affecting the obsolete SSH-1 protocol, both available before host key checking. Vulnerability in all the SSH client tools (PuTTY, Plink, PSFTP, and PSCP) if a malicious program can impersonate Pageant. Crash in GSSAPI / Kerberos key exchange triggered if the server provided an ordinary SSH host key as part of the exchange. Insufficient handling of terminal escape sequences, that should delimit the pasted data in bracketed paste mode (CVE-2019-17068). Possible information leak caused by SSH-1 disconnection messages (CVE-2019-17069). The putty package has been updated to version 0.73, fixing these issues and other bugs. Affected Software/OS: 'putty' package(s) on Mageia 7. Solution: Please install the updated package(s). CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2019-17068 https://lists.tartarus.org/pipermail/putty-announce/2019/000029.html SuSE Security Announcement: openSUSE-SU-2019:2276 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00021.html SuSE Security Announcement: openSUSE-SU-2019:2277 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00020.html SuSE Security Announcement: openSUSE-SU-2019:2292 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00030.html Common Vulnerability Exposure (CVE) ID: CVE-2019-17069 https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |