MGASA-2016-0112
Dashboard / Vulnerabilities / MGASA-2016-0112
Summary: Updated putty packages fix CVE-2016-2563
Details: Updated putty package fixes security vulnerability: Many versions of PSCP in PuTTY prior to 0.67 have a stack corruption vulnerability in their treatment of the 'sink' direction (i.e. downloading from server to client) of the old-style SCP protocol. In order for this vulnerability to be exploited, the user must connect to a malicious server and attempt to download any file (CVE-2016-2563). The putty package has been updated to version 0.67 to fix this issue and a few other bugs. The halibut package has been updated to version 1.1 to build the documentation.
References: https://advisories.mageia.org/MGASA-2016-0112.html, https://bugs.mageia.org/show_bug.cgi?id=17942, http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-pscp-sink-sscanf.html, http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
Affected packages
Package
Name: halibut
Purl: pkg:rpm/mageia/halibut?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
