LICENSEWARE
PuTTY Rule

Releases before 0.81 compromise NIST P-521 keys (CVE-2024-31497)

Catalog row in Vendor License Rules · Cited

Kind
Lifecycle
Statement
Change log, 0.81 (released 2024-04-15): security fix for CVE-2024-31497; NIST P-521 signatures were previously generated with biased nonces, which compromises private keys. The vulnerability record adds that information about existing P-521 private keys has already leaked whenever a signature was made with the old generator, so upgrading alone does not remediate keys already used.
Applies when
Finding PuTTY or Pageant versions earlier than 0.81 in inventory.
Applies to
PuTTY releases before 0.81 and ECDSA NIST P-521 keys used with them
Aliases
CVE-2024-31497; vuln-p521-bias; ecdsa-sha2-nistp521
Esc