6:48 PM

27 October 2004

New version of PuTTY out. Time to upgrade!
SECURITY UPDATE: PuTTY version 0.56 is released ----------------------------------------------- All the pre-built binaries, and the source code, are now available from the PuTTY website at
http://www.chiark.greenend.org.uk/~sgtatham/putty/
This is a SECURITY UPDATE. We recommend that _everybody_ upgrade, as soon as possible. This version fixes a security hole in previous versions of PuTTY, which can allow an SSH2 server to attack your client before host key verification. This means that you are not even safe if you trust the server you _think_ you’re connecting to, since it could be spoofed over the network and the host key check would not detect this before the attack could take place. The attack can allow the server to execute code of its choice on the client.
Computer Log

This is: brett's logjam → October 27, 2004.