Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update putty to v0.71 #2222

Closed
totaam opened this issue Mar 19, 2019 · 1 comment
Closed

update putty to v0.71 #2222

totaam opened this issue Mar 19, 2019 · 1 comment
Labels

Comments

@totaam
Copy link
Collaborator

totaam commented Mar 19, 2019

PuTTY in your hands: SSH client gets patched after RSA key exchange memory vuln spotted: That really is a 'game over' level vulnerability for a secure network protocol: a MITM attacker could bypass the SSH host key system completely.

@totaam
Copy link
Collaborator Author

totaam commented Mar 19, 2019

The problem is that we use the tortoisesvn builds of putty so that we get a GUI for password and key confirmation.
Since we can't wait for them to make a new release, r22126 switches to paramiko as default on win32 (now identical to all the other platforms).

To go back to the previous behaviour, and ignoring the serious security vulnerability (...), use xpra --ssh="C:\Program Files\Xpra\Plink.exe -ssh -noagent".

@totaam totaam closed this as completed Mar 19, 2019
@totaam totaam added the v2.4.x label Jan 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant