Vulnerability in PuTTY allows recovery of user’s private key

In PuTTY, a popular SSH protocol client on the Windows platform, a dangerous vulnerability (CVE-2024-31497) has been identified that allows the reconstruction of a user's private key generated using the ECDSA algorithm with the NIST P-521 elliptic curve (ecdsa-sha2-nistp521). To crack the private key, it is sufficient to analyze approximately 60 digital signatures generated with the problematic key.

The vulnerability manifests starting from PuTTY version 0.68 and has also affected products that include vulnerable versions of PuTTY, such as FileZilla (3.24.1 — 3.66.5), WinSCP (5.9.5 — 6.3.2), TortoiseGit (2.4.0.2 — 2.15.0), and TortoiseSVN (1.10.0 — 1.14.6). The issue has been resolved in the updates of PuTTY 0.81, FileZilla 3.67.0, WinSCP 6.3.3, and TortoiseGit 2.15.0.1. After installing the update, users are advised to generate new keys and remove old public keys from the authorized_keys files.

The vulnerability is due to the negligence of developers who used a 512-bit random sequence-based initialization vector (nonce) for generating the 521-bit key, likely thinking that 512 bits of entropy would be sufficient and that the remaining 9 bits were insignificant. As a result, in all private keys created in PuTTY using the ecdsa-sha2-nistp521 algorithm, the first 9 bits of the initialization vector always took zero values.

For ECDSA and DSA, the quality of the pseudorandom number generator and the complete coverage of random data for the parameter used in the calculation of the modulus are critical, as determining even a few bits of information about the initialization vector is sufficient for conducting an attack to sequentially recover the entire private key. To successfully recover the key, it is enough to have the public key and analyze several dozen digital signatures generated with the problematic key for known data to the attacker. The attack reduces to solving the HNP (Hidden Number Problem).

Necessary digital signatures can be obtained, for example, by connecting a user to an attacker's SSH server or to a Git server using SSH as transport. Signatures required for the attack can also be discovered if the key was used to sign arbitrary data, such as git commits when using the Pageant SSH agent to tunnel traffic to the developer's host. Obtaining the necessary data for key recovery during a MITM attack is excluded since the signatures in SSH are not transmitted in plaintext.

It is noted that a similar use of incomplete initialization vectors was implemented in PuTTY and for other types of elliptic curves; however, for algorithms other than ECDSA P-521, the leaked information is insufficient to mount a working key recovery attack. ECDSA keys of different sizes and Ed25519 keys are not vulnerable to the attack.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster