PuTTY Product Security Update Advisory (CVE-2024-31497)

Overview

 

We have released a security update to address a vulnerability in our PuTTY product. users of affected products are advised to update to the latest version.

 

Affected Products

 

PuTTY versions 0.68 through 0.80

 

Resolved Vulnerabilities

 

Recoverable vulnerability in the private key used in the ECDSA algorithm with NIST P-521 curve (CVE-2024-31497)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

PuTTY version 0.81

 

Referenced Sites

 

[1] CVE-2024-31497: Critical PuTTY Vulnerability Exposes Private Keys – Immediate Action Required

https://securityonline.info/cve-2024-31497-critical-putty-vulnerability-exposes-private-keys-immediate-action-required/?expand_article=1

[2] CVE-2024-31497 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-31497