|
PuTTY contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when session passwords that were stored in the memory during the keyboard-interactive authentication are not properly dumped. This will store passwords within the memory in cleartext until the program stops running, which may disclose password information to a local attacker.
|