PT-2020-13830 · Simon Tatham+1 · Putty+1

Published

2020-06-29

·

Updated

2024-04-25

·

CVE-2020-14002

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PuTTY versions 0.68 through 0.73
Description The issue allows man-in-the-middle attackers to target initial connection attempts where no host key for the server has been cached by the client, due to an Observable Discrepancy leading to an information leak in the algorithm negotiation.
Recommendations For PuTTY versions 0.68 through 0.73, update to a version that contains a fix for this issue to prevent information leaks during algorithm negotiation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1774
ALT-PU-2021-1860
ALT-PU-2023-4867
CVE-2020-14002
DLA-3794-1
MGASA-2020-0358
MGASA-2021-0380

Affected Products

Alt Linux
Putty