Vulnerability in OpenSSH and PuTTY SSH Clients
A vulnerability has been identified in the OpenSSH and PuTTY SSH clients (CVE-2020-14002 in PuTTY and CVE-2020-14145 in OpenSSH) that leads to information leakage in the connection negotiation algorithm. This vulnerability allows an attacker, capable of intercepting client traffic (for instance, when a user connects through a controlled access point), to determine the client's initial connection attempt to the host, before the host key is cached by the client. Knowing that […]
