PuTTY¤Î¥Ç¥¸¥¿¥ë½ð̾¤ËÀȼåÀ¡¢ÈëÌ©¸°¤òÀà¼è¤µ¤ì¤ë²ÄǽÀ
PuTTY¥Á¡¼¥à¤Ï4·î15Æü(±Ñ¹ñ»þ´Ö)¡¢¡ÖPuTTY vulnerability vuln-p521-bias¡×¤Ë¤ª¤¤¤Æ¡¢¥ê¥â¡¼¥È¥í¥°¥ª¥ó¥¯¥é¥¤¥¢¥ó¥È¤Î¡ÖPuTTY¡×¤Ë½ÅÂç¤ÊÀȼåÀ¤¬Â¸ºß¤¹¤ë¤Èȯɽ¤·¤¿¡£¤³¤ÎÀȼåÀ¤ò°ÍѤµ¤ì¤ë¤È¡¢½ð̾ÉÕ¤¥á¥Ã¥»¡¼¥¸¤«¤éÈëÌ©¸°¤ò¼èÆÀ¤µ¤ì¤ë¥ê¥¹¥¯¤¬¤¢¤ë¡£±Æ¶ÁÈϰϤÏPuTTY¤À¤±¤Ç¤Ï¤Ê¤¯¡¢´ØÏ¢¥Ä¡¼¥ë¤È¸°¥Ú¥¢¤ËµÚ¤Ö¤È¤¤¤¦¡£
PuTTY vulnerability vuln-p521-bias
¡ûÀȼåÀ¡ÖCVE-2024-31497¡×¤Î³µÍ×
ȯ¸«¤µ¤ì¤¿ÀȼåÀ¤Ï¡ÖCVE-2024-31497¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë¡£¤³¤Î¥»¥¥å¥ê¥Æ¥£ÀȼåÀ¤ÏPuTTY¤Î½ð̾½èÍý¤Ë¸ºß¤¹¤ë¡£Êƹñ¹ñΩɸ½àµ»½Ñ¸¦µæ½ê(NIST: National Institute of Standards and Technology)¤¬Äê¤á¤¿Âʱ߶ÊÀþP-521¤ò»ÈÍѤ¹¤ëÂʱ߶ÊÀþ¥Ç¥¸¥¿¥ë½ð̾¥¢¥ë¥´¥ê¥º¥à(ECDSA: Elliptic Curve Digital Signature Algorithm)¤Ë¤ª¤¤¤Æ¡¢PuTTY¤ÎÀ¸À®¤¹¤ë¥Î¥ó¥¹(nonce)ÃͤËÊФ꤬¤¢¤ë¤È¤µ¤ì¤ë¡£
DSA¤Î¥Ç¥¸¥¿¥ë½ð̾¥¹¥¡¼¥à¤Ë¤ª¤¤¤Æ»ÈÍѤµ¤ì¤ë¥Î¥ó¥¹(nonce)¤Ï¡¢¤¢¤ë°ìÄê¤ÎÈÏ°ÏÆâ¤Ë¸ºß¤¹¤ë¥é¥ó¥À¥àÃͤȤµ¤ì¤ë¡£¤³¤ÎÃͤËÊФ꤬¤¢¤ë¾ì¹ç¡¢Ê£¿ô¤Î½ð̾¤«¤éÈëÌ©¸°¤ò»»½Ð¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£¤½¤Î¤¿¤á¡¢¥Î¥ó¥¹¤Ë¤Ï°ÂÁ´¤Ê¥é¥ó¥À¥àÃͤλÈÍѤ¬µá¤á¤é¤ì¤ë¡£
PuTTY¤Ï¸Å¤¤Windows¤Ê¤É¤Î°ÂÁ´¤ÊÍð¿ô¤òÀ¸À®¤Ç¤¤Ê¤¤´Ä¶¤ËÂбþ¤¹¤ë¤¿¤á¡¢ÈëÌ©¸°¤È¥á¥Ã¥»¡¼¥¸¤òÆþÎϤ˴ޤà·èÄêÏÀŪÊýË¡¤Ë¤è¤ê¥Î¥ó¥¹ÃͤòÀ¸À®¤·¤Æ¤¤¤¿¡£¶ñÂÎŪ¤Ë¤ÏSHA-512¤ò»ÈÍѤ·¤ÆÆþÎϤ«¤é¥Ï¥Ã¥·¥åÃͤòÀ¸À®¤·¡¢¤³¤ì¤òɬÍפʥӥåȿô¤Ë´Ý¤á¹þ¤à(¾ê;±é»»¤¹¤ë)¡£Âʱ߶ÊÀþP-256¡¢P-384¤Î¾ì¹ç¤ÏSHA-512¤Î¥Ó¥Ã¥È¿ô(512)¤¬¾å²ó¤ë¤¿¤á±é»»·ë²Ì¤Ë¥é¥ó¥À¥àÀ¤ò´üÂԤǤ¤ë¤¬¡¢P-521(521¥Ó¥Ã¥È)¤Î¾ì¹ç¤Ï9¥Ó¥Ã¥ÈÉÔ¤¹¤ë¤¿¤á¡¢¥Î¥ó¥¹¤Î¾å°Ì9¥Ó¥Ã¥È¤¬¾ï¤Ë0¤È¤Ê¤ê¡¢ÊФ꤬ȯÀ¸¤¹¤ë¡£
¡ûÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ëÀ½ÉÊ
ÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ë¤È¤µ¤ì¤ëÀ½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£
PuTTY ¥Ð¡¼¥¸¥ç¥ó0.68¤«¤é0.80¤Þ¤Ç
FileZilla Client ¥Ð¡¼¥¸¥ç¥ó3.24.1¤«¤é3.66.5¤Þ¤Ç
WinSCP ¥Ð¡¼¥¸¥ç¥ó5.9.5¤«¤é6.3.2¤Þ¤Ç
TortoiseGit ¥Ð¡¼¥¸¥ç¥ó2.4.0.2¤«¤é2.15.0¤Þ¤Ç
TortoiseSVN ¥Ð¡¼¥¸¥ç¥ó1.10.0¤«¤é1.14.6¤Þ¤Ç
¡ûÀȼåÀ¤¬½¤Àµ¤µ¤ì¤¿À½ÉÊ
ÀȼåÀ¤¬½¤Àµ¤µ¤ì¤¿À½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£
PuTTY ¥Ð¡¼¥¸¥ç¥ó0.81
FileZilla Client ¥Ð¡¼¥¸¥ç¥ó3.67.0
WinSCP ¥Ð¡¼¥¸¥ç¥ó6.3.3
TortoiseGit ¥Ð¡¼¥¸¥ç¥ó2.15.0.1
TortoiseSVN ¥Ð¡¼¥¸¥ç¥ó1.14.7
¡û±Æ¶Á¤ÈÂкö
PuTTY¤Ë¤è¤ë¤È¡¢¤³¤ÎÀȼåÀ¤ò°ÍѤ¹¤ë¤Ë¤ÏÌó60Ëç¤ÎÅŻҽð̾¤¬É¬ÍפÀ¤È¤¤¤¦¡£²¿¤é¤«¤ÎÊýË¡¤Ç½ð̾¤ò¼ý½¸¤·¤¿¹¶·â¼Ô¤Ï¡¢·×»»¤·¤ÆÆÀ¤é¤ì¤¿ÈëÌ©¸°¤ò»ÈÍѤ·¤Æ½ð̾¤òµ¶Áõ¤·¡¢¥µ¡¼¥Ð¤Ë¿¯Æþ¤¹¤ë²ÄǽÀ¤¬¤¢¤ë¡£
¤³¤ÎÀȼåÀ¤Ï½¤ÀµÁ°¤ÎPuTTY¤Ë¤è¤Ã¤ÆÀ¸À®¤µ¤ì¤¿Âʱ߶ÊÀþP-521¤ò»ÈÍѤ¹¤ëÅŻҽð̾¤¹¤Ù¤Æ¤Ë±Æ¶Á¤·¤Æ¤ª¤ê¡¢ÈëÌ©¸°¤Î°ÂÁ´À¤â¤³¤ì¤éÅŻҽð̾¤Ë¤è¤ê¼º¤ï¤ì¤Æ¤¤¤ë¤Èɾ²Á¤Ç¤¤ë¡£¤½¤Î¤¿¤á¡¢±Æ¶Á¤ò¼õ¤±¤ë¤³¤ì¤éÅŻҽð̾¤È¸°¥Ú¥¢¤Ï¤¹¤Ù¤ÆÇË´þ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
¤Ê¤ª¡¢¤³¤ÎÀȼåÀ¤Ï¸°¥Ú¥¢¤Ç¤Ï¤Ê¤¯ÅŻҽð̾¤Ë±Æ¶Á¤·¤Æ¤¤¤ëÅÀ¤ËÃí°Õ¤¬É¬Íס£¸°¥Ú¥¢¤ò¾¤Î¥½¥Õ¥È¥¦¥§¥¢¤«¤éÀ¸À®¤·¤Æ¤¤¤¿¤È¤·¤Æ¤â¡¢¤³¤ÎÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ëÅŻҽð̾¤Ë¤è¤êÈëÌ©¸°¤¬·×»»¤Ç¤¤ë²ÄǽÀ¤¬¤¢¤ë¤¿¤á¡¢¤½¤Î¸°¥Ú¥¢¤â¤¹¤Ç¤Ë°ÂÁ´¤Ç¤Ï¤Ê¤¤¡£
±Æ¶Á¤ò¼õ¤±¤ëÀ½Éʤò»ÈÍѤ·¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤Ë¤Ï¡¢¤¹¤Ù¤Æ¤ÎÀ½Éʤò¥¢¥Ã¥×¥Ç¡¼¥È¤·¡¢É¬Íפ˱þ¤¸¤Æ¸°¥Ú¥¢¤ÈÅŻҽð̾¤òºÆÀ¸À®¤·¤ÆÃÖ¤´¹¤¨¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
PuTTY vulnerability vuln-p521-bias
ȯ¸«¤µ¤ì¤¿ÀȼåÀ¤Ï¡ÖCVE-2024-31497¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤¤¤ë¡£¤³¤Î¥»¥¥å¥ê¥Æ¥£ÀȼåÀ¤ÏPuTTY¤Î½ð̾½èÍý¤Ë¸ºß¤¹¤ë¡£Êƹñ¹ñΩɸ½àµ»½Ñ¸¦µæ½ê(NIST: National Institute of Standards and Technology)¤¬Äê¤á¤¿Âʱ߶ÊÀþP-521¤ò»ÈÍѤ¹¤ëÂʱ߶ÊÀþ¥Ç¥¸¥¿¥ë½ð̾¥¢¥ë¥´¥ê¥º¥à(ECDSA: Elliptic Curve Digital Signature Algorithm)¤Ë¤ª¤¤¤Æ¡¢PuTTY¤ÎÀ¸À®¤¹¤ë¥Î¥ó¥¹(nonce)ÃͤËÊФ꤬¤¢¤ë¤È¤µ¤ì¤ë¡£
DSA¤Î¥Ç¥¸¥¿¥ë½ð̾¥¹¥¡¼¥à¤Ë¤ª¤¤¤Æ»ÈÍѤµ¤ì¤ë¥Î¥ó¥¹(nonce)¤Ï¡¢¤¢¤ë°ìÄê¤ÎÈÏ°ÏÆâ¤Ë¸ºß¤¹¤ë¥é¥ó¥À¥àÃͤȤµ¤ì¤ë¡£¤³¤ÎÃͤËÊФ꤬¤¢¤ë¾ì¹ç¡¢Ê£¿ô¤Î½ð̾¤«¤éÈëÌ©¸°¤ò»»½Ð¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£¤½¤Î¤¿¤á¡¢¥Î¥ó¥¹¤Ë¤Ï°ÂÁ´¤Ê¥é¥ó¥À¥àÃͤλÈÍѤ¬µá¤á¤é¤ì¤ë¡£
PuTTY¤Ï¸Å¤¤Windows¤Ê¤É¤Î°ÂÁ´¤ÊÍð¿ô¤òÀ¸À®¤Ç¤¤Ê¤¤´Ä¶¤ËÂбþ¤¹¤ë¤¿¤á¡¢ÈëÌ©¸°¤È¥á¥Ã¥»¡¼¥¸¤òÆþÎϤ˴ޤà·èÄêÏÀŪÊýË¡¤Ë¤è¤ê¥Î¥ó¥¹ÃͤòÀ¸À®¤·¤Æ¤¤¤¿¡£¶ñÂÎŪ¤Ë¤ÏSHA-512¤ò»ÈÍѤ·¤ÆÆþÎϤ«¤é¥Ï¥Ã¥·¥åÃͤòÀ¸À®¤·¡¢¤³¤ì¤òɬÍפʥӥåȿô¤Ë´Ý¤á¹þ¤à(¾ê;±é»»¤¹¤ë)¡£Âʱ߶ÊÀþP-256¡¢P-384¤Î¾ì¹ç¤ÏSHA-512¤Î¥Ó¥Ã¥È¿ô(512)¤¬¾å²ó¤ë¤¿¤á±é»»·ë²Ì¤Ë¥é¥ó¥À¥àÀ¤ò´üÂԤǤ¤ë¤¬¡¢P-521(521¥Ó¥Ã¥È)¤Î¾ì¹ç¤Ï9¥Ó¥Ã¥ÈÉÔ¤¹¤ë¤¿¤á¡¢¥Î¥ó¥¹¤Î¾å°Ì9¥Ó¥Ã¥È¤¬¾ï¤Ë0¤È¤Ê¤ê¡¢ÊФ꤬ȯÀ¸¤¹¤ë¡£
¡ûÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ëÀ½ÉÊ
ÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ë¤È¤µ¤ì¤ëÀ½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£
PuTTY ¥Ð¡¼¥¸¥ç¥ó0.68¤«¤é0.80¤Þ¤Ç
FileZilla Client ¥Ð¡¼¥¸¥ç¥ó3.24.1¤«¤é3.66.5¤Þ¤Ç
WinSCP ¥Ð¡¼¥¸¥ç¥ó5.9.5¤«¤é6.3.2¤Þ¤Ç
TortoiseGit ¥Ð¡¼¥¸¥ç¥ó2.4.0.2¤«¤é2.15.0¤Þ¤Ç
TortoiseSVN ¥Ð¡¼¥¸¥ç¥ó1.10.0¤«¤é1.14.6¤Þ¤Ç
¡ûÀȼåÀ¤¬½¤Àµ¤µ¤ì¤¿À½ÉÊ
ÀȼåÀ¤¬½¤Àµ¤µ¤ì¤¿À½Éʤª¤è¤Ó¥Ð¡¼¥¸¥ç¥ó¤Ï¼¡¤Î¤È¤ª¤ê¡£
PuTTY ¥Ð¡¼¥¸¥ç¥ó0.81
FileZilla Client ¥Ð¡¼¥¸¥ç¥ó3.67.0
WinSCP ¥Ð¡¼¥¸¥ç¥ó6.3.3
TortoiseGit ¥Ð¡¼¥¸¥ç¥ó2.15.0.1
TortoiseSVN ¥Ð¡¼¥¸¥ç¥ó1.14.7
¡û±Æ¶Á¤ÈÂкö
PuTTY¤Ë¤è¤ë¤È¡¢¤³¤ÎÀȼåÀ¤ò°ÍѤ¹¤ë¤Ë¤ÏÌó60Ëç¤ÎÅŻҽð̾¤¬É¬ÍפÀ¤È¤¤¤¦¡£²¿¤é¤«¤ÎÊýË¡¤Ç½ð̾¤ò¼ý½¸¤·¤¿¹¶·â¼Ô¤Ï¡¢·×»»¤·¤ÆÆÀ¤é¤ì¤¿ÈëÌ©¸°¤ò»ÈÍѤ·¤Æ½ð̾¤òµ¶Áõ¤·¡¢¥µ¡¼¥Ð¤Ë¿¯Æþ¤¹¤ë²ÄǽÀ¤¬¤¢¤ë¡£
¤³¤ÎÀȼåÀ¤Ï½¤ÀµÁ°¤ÎPuTTY¤Ë¤è¤Ã¤ÆÀ¸À®¤µ¤ì¤¿Âʱ߶ÊÀþP-521¤ò»ÈÍѤ¹¤ëÅŻҽð̾¤¹¤Ù¤Æ¤Ë±Æ¶Á¤·¤Æ¤ª¤ê¡¢ÈëÌ©¸°¤Î°ÂÁ´À¤â¤³¤ì¤éÅŻҽð̾¤Ë¤è¤ê¼º¤ï¤ì¤Æ¤¤¤ë¤Èɾ²Á¤Ç¤¤ë¡£¤½¤Î¤¿¤á¡¢±Æ¶Á¤ò¼õ¤±¤ë¤³¤ì¤éÅŻҽð̾¤È¸°¥Ú¥¢¤Ï¤¹¤Ù¤ÆÇË´þ¤¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£
¤Ê¤ª¡¢¤³¤ÎÀȼåÀ¤Ï¸°¥Ú¥¢¤Ç¤Ï¤Ê¤¯ÅŻҽð̾¤Ë±Æ¶Á¤·¤Æ¤¤¤ëÅÀ¤ËÃí°Õ¤¬É¬Íס£¸°¥Ú¥¢¤ò¾¤Î¥½¥Õ¥È¥¦¥§¥¢¤«¤éÀ¸À®¤·¤Æ¤¤¤¿¤È¤·¤Æ¤â¡¢¤³¤ÎÀȼåÀ¤Î±Æ¶Á¤ò¼õ¤±¤ëÅŻҽð̾¤Ë¤è¤êÈëÌ©¸°¤¬·×»»¤Ç¤¤ë²ÄǽÀ¤¬¤¢¤ë¤¿¤á¡¢¤½¤Î¸°¥Ú¥¢¤â¤¹¤Ç¤Ë°ÂÁ´¤Ç¤Ï¤Ê¤¤¡£
±Æ¶Á¤ò¼õ¤±¤ëÀ½Éʤò»ÈÍѤ·¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤Ë¤Ï¡¢¤¹¤Ù¤Æ¤ÎÀ½Éʤò¥¢¥Ã¥×¥Ç¡¼¥È¤·¡¢É¬Íפ˱þ¤¸¤Æ¸°¥Ú¥¢¤ÈÅŻҽð̾¤òºÆÀ¸À®¤·¤ÆÃÖ¤´¹¤¨¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£