Re: PuTTy and Insecurely Stored Passwords

From: Jacob Nevins (jacobn@chiark.greenend.org.uk)
Date: 01/30/03


From: Jacob Nevins <jacobn@chiark.greenend.org.uk>
Date: 30 Jan 2003 12:46:32 +0000 (GMT)

K C <k36s@gosympatico.ca> writes:
>Any news, status of fix(es) re: 'SSH2 Clients Insecurely Store
>Passwords (AbsoluteTelnet, SecureCRT, Entunnel, SecureFx, and PuTTY)'
>[1] ??
>1 - http://www.securiteam.com/securitynews/5DP0K2K8VI.html

The reference you gave states:

| Current development snapshots of PuTTY are believed to have this
| problem fixed. Unfortunately, we are in the middle of heavy code
| restructuring and not currently in a position to make a stable
| release, but the current snapshots should be good enough for anyone
| for whom this is a problem.

In particular, PuTTY development snapshots from 2003-01-10 onwards
contain the fix, as will the next stable release (whenever that may
be).