https://seclists.org/oss-sec/2024/q2/122: CVE-2024-31497: Secret Key Recovery of NIST P-521 Private Keys Through Biased ECDSA Nonces in PuTTY Client
Published Apr 15, 2024
·Updated
Affected Software
1 affected component
Putty PuTTY Client
Frequently Asked Questions
1
What is the severity of CVE-2024-31497?
CVE-2024-31497 is classified as high severity due to the potential for secret key recovery.
2
How do I fix CVE-2024-31497?
To fix CVE-2024-31497, users should ensure they are using the latest version of the PuTTY client that incorporates security patches.
3
What vulnerabilities does CVE-2024-31497 exploit?
CVE-2024-31497 exploits biased ECDSA nonces to recover NIST P-521 private keys.
4
Can the impact of CVE-2024-31497 lead to unauthorized access?
Yes, if exploited, CVE-2024-31497 can lead to unauthorized access through the recovery of private keys.
5
Who is impacted by CVE-2024-31497?
CVE-2024-31497 affects all users of the PuTTY client who utilize NIST P-521 for ECDSA signatures.