1
0
mirror of https://git.tartarus.org/simon/putty.git synced 2025-01-09 17:38:00 +00:00
Go to file
Simon Tatham 4510a622ea Tighten up a comparison in ssh2_userauth_add_sigblob.
If a malicious SSH agent were to send an RSA signature blob _longer_
than the key modulus while BUG_SSH2_RSA_PADDING was enabled, then it
could DoS the client, because the put_padding call would keep
allocating memory in 'strbuf *substr' until address space ran out.
2020-06-21 16:39:47 +01:00
charset Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
contrib kh2reg: stop using deprecated base64.decodestring. 2020-06-14 15:49:36 +01:00
doc Docs: use less personalised example Windows prompts. 2020-06-21 16:39:47 +01:00
icons Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
test Fix mp_{eq,hs}_integer(tiny, huge). 2020-06-14 15:49:36 +01:00
unix uxucs.c: fix type of wcrtomb return value. 2020-06-14 15:49:36 +01:00
windows Remove white dialog background in MSI user interface. 2020-06-21 16:39:47 +01:00
.gitignore New utility object, StripCtrlChars. 2019-02-20 07:27:22 +00:00
agentf.c
aqsync.c
be_all_s.c
be_all.c
be_misc.c
be_none.c
be_nos_s.c
be_nossh.c
be_ssh.c
Buildscr Remove white dialog background in MSI user interface. 2020-06-21 16:39:47 +01:00
Buildscr.cv Turn off hardware AES for the Coverity build. 2019-05-05 08:38:37 +01:00
callback.c
cgtest.c
CHECKLST.txt Release checklist updates post-0.72. 2019-07-20 08:13:07 +01:00
cmdgen.c cgtest: add missing \n in an error message. 2020-02-09 08:51:37 +00:00
cmdline.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
conf.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
config.c Make dupcat() into a variadic macro. 2019-10-14 19:42:37 +01:00
configure.ac
cproxy.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
defs.h New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
dialog.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
dialog.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ecc.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ecc.h
errsock.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
fuzzterm.c fuzzterm.c: fix prototypes of stub dlg functions. 2020-06-14 15:49:36 +01:00
import.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
LATEST.VER Update version number for 0.73 release. 2019-09-22 10:12:29 +01:00
ldisc.c Remove assertion that len != 0 in ldisc_send. 2020-06-14 15:49:36 +01:00
ldisc.h
LICENCE It is, once again, a new year. 2020-02-09 08:19:21 +00:00
licence.pl
logging.c New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
mainchan.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
marshal.c Add BinarySource_REWIND_TO. 2020-02-09 08:21:21 +00:00
marshal.h Add BinarySource_REWIND_TO. 2020-02-09 08:21:21 +00:00
memory.c Fix undefined behaviour in safegrowarray. 2020-02-09 08:51:37 +00:00
minibidi.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
misc.c Fix format string mistakes revealed by new checking. 2020-02-09 08:51:37 +00:00
misc.h Greatly improve printf format-string checking. 2020-02-09 08:51:37 +00:00
miscucs.c
mkauto.sh
mkfiles.pl Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
mksrcarc.sh
mkunxarc.sh
mpint_i.h Fix technical-UB uses of the preprocessor. 2020-02-09 08:51:37 +00:00
mpint.c Fix mp_{eq,hs}_integer(tiny, huge). 2020-06-14 15:49:36 +01:00
mpint.h
network.h Greatly improve printf format-string checking. 2020-02-09 08:51:37 +00:00
nocmdline.c Replace assert(false) with an unreachable() macro. 2019-01-03 08:12:28 +00:00
nocproxy.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
nogss.c
noprint.c
noshare.c
noterm.c
notiming.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
nullplug.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
pageant.c Minor memory leaks in Pageant client code. 2020-06-14 15:49:36 +01:00
pageant.h
pgssapi.c
pgssapi.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
pinger.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
portfwd.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
pproxy.c
proxy.c Fix handling of string-typed address from SOCKS5 server. 2019-10-01 19:31:37 +01:00
proxy.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
pscp.c Fix a deadlock in SFTP upload. 2020-06-14 15:49:36 +01:00
psftp.c Fix minor memory leak in psftp batch mode. 2020-06-14 15:49:36 +01:00
psftp.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
psftpcommon.c Fall back to not sorting large dirs in pscp -ls or psftp 'ls'. 2019-07-10 20:47:09 +01:00
putty.h Make prototype for new_prompts() consistent. 2020-02-09 08:51:37 +00:00
puttymem.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
puttyps.h
raw.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
README
Recipe Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
release.pl Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
resource.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
rlogin.c Use strbuf to store results in prompts_t. 2020-02-09 08:51:37 +00:00
scpserver.c Greatly improve printf format-string checking. 2020-02-09 08:51:37 +00:00
sercfg.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sesschan.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sessprep.c sessprep: fix detection of unbracketed IPv6 literals. 2019-03-22 16:32:41 +00:00
settings.c Make dupcat() into a variadic macro. 2019-10-14 19:42:37 +01:00
sftp.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sftp.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sftpcommon.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sftpserver.c Fix two accidental overwrites of 'flags'. 2020-02-09 08:51:37 +00:00
sign.sh Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ssh1bpp.c Track the total size of every PacketQueue. 2020-02-09 08:51:37 +00:00
ssh1censor.c
ssh1connection-client.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ssh1connection-server.c
ssh1connection.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh1connection.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ssh1login-server.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh1login.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh2bpp-bare.c Track the total size of every PacketQueue. 2020-02-09 08:51:37 +00:00
ssh2bpp.c Track the total size of every PacketQueue. 2020-02-09 08:51:37 +00:00
ssh2censor.c
ssh2connection-client.c Fix null-dereference in ssh2_channel_response. 2020-06-14 15:49:36 +01:00
ssh2connection-server.c
ssh2connection.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh2connection.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ssh2kex-client.c GSS kex: remove spurious no-op assignment. 2019-05-05 10:25:01 +01:00
ssh2kex-server.c New functions to shrink a strbuf. 2020-02-09 08:51:37 +00:00
ssh2transhk.c Add missing del234 in ssh_transient_hostkey_cache_add. 2019-06-15 21:37:36 +01:00
ssh2transport.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh2transport.h
ssh2userauth-server.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh2userauth.c Tighten up a comparison in ssh2_userauth_add_sigblob. 2020-06-21 16:39:47 +01:00
ssh.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
ssh.h Track the total size of every PacketQueue. 2020-02-09 08:51:37 +00:00
sshaes.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
ssharcf.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshauxcrypt.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshbcrypt.c
sshblowf.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshblowf.h
sshbpp.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshccp.c
sshchan.h
sshcommon.c Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
sshcr.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshcrc.c
sshcrcda.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshdes.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshdh.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshdss.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshdssg.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshecc.c PuTTYgen: permit and prefer 255 as bit count for ed25519. 2020-02-09 08:51:37 +00:00
sshecdsag.c
sshgss.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshgssc.c Make dupcat() into a variadic macro. 2019-10-14 19:42:37 +01:00
sshgssc.h
sshhmac.c Fix text name of hmac-sha1-96-buggy. 2020-02-09 08:51:37 +00:00
sshmac.c
sshmd5.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshnogss.c
sshppl.h Account for packet queues in ssh_sendbuffer(). 2020-02-09 08:51:37 +00:00
sshprime.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshprng.c New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
sshpubk.c New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
sshrand.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshrsa.c New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
sshrsag.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshserver.c sshserver.c: fix prototype of mainchan_new. 2020-06-14 15:49:36 +01:00
sshserver.h
sshsh256.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshsh512.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshsha.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
sshshare.c Fix format string mistakes revealed by new checking. 2020-02-09 08:51:37 +00:00
sshsignals.h
sshttymodes.h
sshverstring.c New functions to shrink a strbuf. 2020-02-09 08:51:37 +00:00
sshzlib.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
storage.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
stripctrl.c stripctrl: clean up precarious handling of 'width'. 2019-07-23 19:58:48 +01:00
telnet.c New functions to shrink a strbuf. 2020-02-09 08:51:37 +00:00
terminal.c Remove obsolete checks for ldisc_send with len == 0. 2020-06-14 15:49:36 +01:00
terminal.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
testback.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
testcrypt.c Fix technical-UB uses of the preprocessor. 2020-02-09 08:51:37 +00:00
testcrypt.h Fix text name of hmac-sha1-96-buggy. 2020-02-09 08:51:37 +00:00
testsc.c New wrapper macro for printf("%zu"), for old VS compat. 2020-02-09 08:51:37 +00:00
testzlib.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
time.c
timing.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
tree234.c Greatly improve printf format-string checking. 2020-02-09 08:51:37 +00:00
tree234.h Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
utils.c Introduce and use strbuf_chomp. 2020-02-09 08:51:37 +00:00
version.c
version.h
wcwidth.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
wildcard.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00
x11fwd.c Whitespace rationalisation of entire code base. 2019-09-08 20:29:21 +01:00

This is the README for the source archive of PuTTY, a free Windows
and Unix Telnet and SSH client.

If you want to rebuild PuTTY from source, we provide a variety of
Makefiles and equivalents. (If you have fetched the source from
Git, you'll have to generate the Makefiles yourself -- see
below.)

There are various compile-time directives that you can use to
disable or modify certain features; it may be necessary to do this
in some environments. They are documented in `Recipe', and in
comments in many of the generated Makefiles.

For building on Windows:

 - windows/Makefile.vc is for command-line builds on MS Visual C++
   systems. Change into the `windows' subdirectory and type `nmake
   -f Makefile.vc' to build all the PuTTY binaries.

   As of 2017, we successfully compile PuTTY with both Visual Studio
   7 (2003) and Visual Studio 14 (2015), so our guess is that it will
   probably build with versions in between those as well.

   (The binaries from Visual Studio 14 are only compatible with
   Windows XP and up. Binaries from Visual Studio 7 ought to work
   with anything from Windows 95 onward.)

 - Inside the windows/MSVC subdirectory are MS Visual Studio project
   files for doing GUI-based builds of the various PuTTY utilities.
   These have been tested on Visual Studio 7 and 10.

   You should be able to build each PuTTY utility by loading the
   corresponding .dsp file in Visual Studio. For example,
   MSVC/putty/putty.dsp builds PuTTY itself, MSVC/plink/plink.dsp
   builds Plink, and so on.

 - windows/Makefile.mgw is for MinGW / Cygwin installations. Type
   `make -f Makefile.mgw' while in the `windows' subdirectory to
   build all the PuTTY binaries.

   MinGW and friends can lag behind other toolchains in their support
   for the Windows API. Compile-time levers are provided to exclude
   some features; the defaults are set appropriately for the
   'mingw-w64' cross-compiler provided with Ubuntu 14.04. If you are
   using an older toolchain, you may need to exclude more features;
   alternatively, you may find that upgrading to a recent version of
   the 'w32api' package helps.

 - windows/Makefile.lcc is for lcc-win32. Type `make -f
   Makefile.lcc' while in the `windows' subdirectory. (You will
   probably need to specify COMPAT=-DNO_MULTIMON.)

 - Inside the windows/DEVCPP subdirectory are Dev-C++ project
   files for doing GUI-based builds of the various PuTTY utilities.

The PuTTY team actively use Makefile.vc (with VC7/10) and Makefile.mgw
(with mingw32), so we'll probably notice problems with those
toolchains fairly quickly. Please report any problems with the other
toolchains mentioned above.

For building on Unix:

 - unix/configure is for Unix and GTK. If you don't have GTK, you
   should still be able to build the command-line utilities (PSCP,
   PSFTP, Plink, PuTTYgen) using this script. To use it, change into
   the `unix' subdirectory, run `./configure' and then `make'. Or you
   can do the same in the top-level directory (we provide a little
   wrapper that invokes configure one level down), which is more like
   a normal Unix source archive but doesn't do so well at keeping the
   per-platform stuff in each platform's subdirectory; it's up to you.

 - unix/Makefile.gtk and unix/Makefile.ux are for non-autoconfigured
   builds. These makefiles expect you to change into the `unix'
   subdirectory, then run `make -f Makefile.gtk' or `make -f
   Makefile.ux' respectively. Makefile.gtk builds all the programs but
   relies on Gtk, whereas Makefile.ux builds only the command-line
   utilities and has no Gtk dependence.

 - For the graphical utilities, any of Gtk+-1.2, Gtk+-2.0, and Gtk+-3.0
   should be supported. If you have more than one installed, you can
   manually specify which one you want by giving the option
   '--with-gtk=N' to the configure script where N is 1, 2, or 3.
   (The default is the newest available, of course.) In the absence
   of any Gtk version, the configure script will automatically
   construct a Makefile which builds only the command-line utilities;
   you can manually create this condition by giving configure the
   option '--without-gtk'.

 - pterm would like to be setuid or setgid, as appropriate, to permit
   it to write records of user logins to /var/run/utmp and
   /var/log/wtmp. (Of course it will not use this privilege for
   anything else, and in particular it will drop all privileges before
   starting up complex subsystems like GTK.) By default the makefile
   will not attempt to add privileges to the pterm executable at 'make
   install' time, but you can ask it to do so by running configure
   with the option '--enable-setuid=USER' or '--enable-setgid=GROUP'.

 - The Unix Makefiles have an `install' target. Note that by default
   it tries to install `man' pages; if you have fetched the source via
   Git then you will need to have built these using Halibut
   first - see below.

 - It's also possible to build the Windows version of PuTTY to run
   on Unix by using Winelib.  To do this, change to the `windows'
   directory and run `make -f Makefile.mgw CC=winegcc RC=wrc'.

All of the Makefiles are generated automatically from the file
`Recipe' by the Perl script `mkfiles.pl' (except for the Unix one,
which is generated by the `configure' script; mkfiles.pl only
generates the input to automake). Additions and corrections to Recipe,
mkfiles.pl and/or configure.ac are much more useful than additions and
corrections to the actual Makefiles, Makefile.am or Makefile.in.

The Unix `configure' script and its various requirements are generated
by the shell script `mkauto.sh', which requires GNU Autoconf, GNU
Automake, and Gtk; if you've got the source from Git rather
than using one of our source snapshots, you'll need to run this
yourself. The input file to Automake is generated by mkfiles.pl along
with all the rest of the makefiles, so you will need to run mkfiles.pl
and then mkauto.sh.

Documentation (in various formats including Windows Help and Unix
`man' pages) is built from the Halibut (`.but') files in the `doc'
subdirectory using `doc/Makefile'. If you aren't using one of our
source snapshots, you'll need to do this yourself. Halibut can be
found at <https://www.chiark.greenend.org.uk/~sgtatham/halibut/>.

The PuTTY home web site is

    https://www.chiark.greenend.org.uk/~sgtatham/putty/

If you want to send bug reports or feature requests, please read the
Feedback section of the web site before doing so. Sending one-line
reports saying `it doesn't work' will waste your time as much as
ours.

See the file LICENCE for the licence conditions.