Releases before 0.81 compromise NIST P-521 keys (CVE-2024-31497)
Catalog row in Vendor License Rules · Cited
- Kind
- Lifecycle
- Statement
- Change log, 0.81 (released 2024-04-15): security fix for CVE-2024-31497; NIST P-521 signatures were previously generated with biased nonces, which compromises private keys. The vulnerability record adds that information about existing P-521 private keys has already leaked whenever a signature was made with the old generator, so upgrading alone does not remediate keys already used.
- Applies when
- Finding PuTTY or Pageant versions earlier than 0.81 in inventory.
- Applies to
- PuTTY releases before 0.81 and ECDSA NIST P-521 keys used with them
- Aliases
- CVE-2024-31497; vuln-p521-bias; ecdsa-sha2-nistp521