VDB
GCVE-110-MAGEIA-2021-380
GCVE-110-MAGEIA-2021-380
Advisory Published
filezilla embeds a PuTTY client that was vulnerable:
PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an
information leak in the algorithm negotiation. This allows man-in-the-middle
attackers to target initial connection attempts (where no host key for the
server has been cached by the client) (CVE-2020-14002).
The filezilla packages are updated to fix this issue to 3.55.0 version among
other bugfixes since 3.51.0 we shipped in Mageia 8. See upstream release notes
for more informations.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | libfilezilla | 0 (affected), 0.30.0-1.mga8 (unaffected) | — |
| Mageia | filezilla | 0 (affected), 3.55.0-1.mga8 (unaffected) | — |
Aliases
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.