There is a bug in SSH2 support that allows a server to execute
malicious code on a connecting PuTTY client.
This attack can be performed before host key verification happens,
so a different machine -- man in the middle attack -- could fake
the machine you are connecting to.