Post a reply

Before posting, please read how to report bug or request support effectively.

Bug reports without an attached log file are usually useless.

Add an Attachment

If you do not want to add an Attachment to your Post, please leave the Fields blank.

(maximum 10 MB; please compress large files; only common media, archive, text and programming file formats are allowed)


Topic review


I have removed the mention of "PuTTY 0.80", so that people don't get confused.

Ok, those are major changes in WinSCP 6.3 release from February.
It does not include changes in later hotfixes.
If you click on "List of all changes", you will see PuTTY 0.81.

On the download page it says
SSH core upgraded to PuTTY 0.80. That includes support for HMAC-SHA-512 and mitigation of “Terrapin” vulnerability.

Download notes for 6.3.3 and CVE-2024-31497

The Download notes for 6.3.3 say:
SSH core upgraded to PuTTY 0.80.

But I thought that version has the vulnerability, unless "SSH core" version is
different from the PuTTY executable version.