{"id":"MGASA-2024-0140","summary":"Updated putty & filezilla packages fix security vulnerability","details":"The PuTTY client and all related components generate heavily biased\nECDSA nonces in the case of NIST P-521. To be more precise, the first 9\nbits of each ECDSA nonce are zero. This allows for full secret key\nrecovery in roughly 60 signatures by using state-of-the-art techniques.\nThese signatures can either be harvested by a malicious server\n(man-in-the-middle attacks are not possible given that clients do not\ntransmit their signature in the clear) or from any other source, e.g.\nsigned git commits through forwarded agents. The nonce generation for\nother curves is slightly biased as well. However, the bias is negligible\nand far from enough to perform lattice-based key recovery attacks (not\nconsidering cryptanalytical advancements).\n","modified":"2026-04-16T00:09:10.539716787Z","published":"2024-04-20T18:11:17Z","upstream":["CVE-2024-31497"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0140.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33103"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/04/15/6"}],"affected":[{"package":{"name":"putty","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/putty?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.81-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0140.json"}},{"package":{"name":"filezilla","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/filezilla?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.67.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0140.json"}},{"package":{"name":"libfilezilla","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libfilezilla?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.47.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0140.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}