Product:

Winscp

(Winscp)
Date Id Summary Products Score Patch Annotated
2024-04-15 CVE-2024-31497 In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant... Fedora, Filezilla_client, Putty, Tortoisesvn, Tortoisegit, Winscp 5.9