CVE-2021-36367

Name
CVE-2021-36367
Description
PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
MISC https://git.tartarus.org/?p=simon/putty.git;a=commit;h=1dc5659aa62848f0aeb5de7bd3839fecc7debefa
cve@mitre.org https://git.tartarus.org/?p=simon/putty.git%3Ba=commit%3Bh=1dc5659aa62848f0aeb5de7bd3839fecc7debefa
vendor-advisory https://www.debian.org/security/2023/dsa-5588
mailing-list https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
putty edge-main 0.76-r0 Jeff Bilyk <jbilyk@alpinelinux.org> fixed
putty edge-community 0.76-r0 None fixed
putty 3.22-community 0.76-r0 None fixed
putty 3.21-community 0.76-r0 None fixed
putty 3.20-community 0.76-r0 None fixed
putty 3.19-main 0.76-r0 None fixed
putty 3.18-main 0.76-r0 None fixed
putty 3.17-main 0.76-r0 None fixed
putty 3.12-main 0.76-r0 Jeff Bilyk <jbilyk@alpinelinux.org> fixed
putty 3.12-main 0.74-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable
putty 3.11-main 0.76-r0 Jeff Bilyk <jbilyk@alpinelinux.org> fixed
putty 3.11-main 0.74-r0 Jeff Bilyk <jbilyk@alpinelinux.org> possibly vulnerable