CVE-2019-9898Use of Insufficiently Random Values in Putty

Severity
9.8CRITICALNVD
EPSS
4.3%
top 11.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDputty/putty< 0.71
debiandebian/putty< putty 0.70-6 (bookworm)
Debianputty/putty< 0.70-6+3
NVDopensuse/leap15.0

Also affects: Debian Linux 8.0, 9.0, Fedora 28, 29

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8px9-pwgj-xj9f: Potential recycling of random numbers used in cryptography exists within PuTTY before 02022-05-13
OSV
CVE-2019-9898: Potential recycling of random numbers used in cryptography exists within PuTTY before 02019-03-21

📋Vendor Advisories

1
Debian
CVE-2019-9898: putty - Potential recycling of random numbers used in cryptography exists within PuTTY b...2019

💬Community

3
Bugzilla
CVE-2019-9894 CVE-2019-9895 CVE-2019-9898 CVE-2019-9897 putty: multiple vulnerabilities2019-03-19
Bugzilla
CVE-2019-9894 CVE-2019-9895 CVE-2019-9898 CVE-2019-9897 putty: multiple vulnerabilities [epel-all]2019-03-19
Bugzilla
CVE-2019-9894 CVE-2019-9895 CVE-2019-9898 CVE-2019-9897 putty: multiple vulnerabilities [fedora-all]2019-03-19