|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-31497: filezilla: putty: NIST P521 private keys are exposed by biased signature generation | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | Marcus Meissner <meissner> |
| Component: | Security | Assignee: | Eric Schirra <ecsos> |
| Status: | IN_PROGRESS --- | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | Andreas.Stieger, jengelh, meissner, security-team |
| Version: | Leap 15.5 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/401933/ | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2024-04-16 07:21:59 UTC
And what have an bug in putty to do with filezilla? Think this a wrong place and should adressed to putty. filezilla ships a bundled source code copy of putty, that's why. (In reply to Eric Schirra from comment #1) > And what have an bug in putty to do with filezilla? > Think this a wrong place and should adressed to putty. Defined in package: network/filezilla bugowner of filezilla : - maintainer of filezilla : ecsos@schirra.net The issue is that filezilla has putty in src/putty/ as embedded library / code. I would just wait that filezilla releases this as update. > 2024-04-15 - FileZilla Client 3.67.0 released > SFTP: Fixed PuTTY ECDSA NIST P-521 private key recovery vulnerability (CVE-2024-31497). If you use NIST P-521 keys to connect to SSH/SFTP servers, you should regenerate them and revoke the previous ones. Code fix for backporting: https://svn.filezilla-project.org/filezilla?view=revision&revision=11142 https://build.opensuse.org/request/show/1168540 Eric I'll see later (this week) how this could be brought into Leap... |