Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

openSUSE 15-SP3: 2022:0061-1 Moderate: sftp Fingerprint Verification Issue

opensuse
Calendar Grey March 1, 2022
Dist Opensuse Esm H88
A crucial patch has been released for mc that addresses significant vulnerabilities, notably enhancing server identity verification in openSUSE.
An update that fixes one vulnerability is now available

Description

This update for mc fixes the following issues:

Midnight Commander 4.8.27:

* Core

- Reimplement version detection (#3603, #4249)

- Significantly reduce rebuilt time after version change (#2252, #4266)

- Drop automatic migration of configuration from ~/.mc to XDG-based

directories (#3682)

- zsh: support custom configuration file: ~/.local/share/mc/.zshrc

(#4203)

- Widgets: implement WST_VISIBLE state to show/hide widgets (#2919)

- Find File: add Follow symlinks option (#2020)

* VFS

- extfs: support unrar-6 (#4154)

- extfs: support official 7z binary (7zz) (#4239)

- ftpfs: apply file list parser from lftp project (#2841, #3174)

* Editor

- Word completion: get candidates from all open files (#4160)

- etags: get rid of hardcoded list length and window width (#4132)

- Update syntax files:

- python (#4140)

- Add syntax highlighting:

- Verilog and SystemVerilog? header files...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-61=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):

mc-4.8.27-bp153.2.3.1

- openSUSE Backports SLE-15-SP3 (noarch):

mc-lang-4.8.27-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2021-36370.html

https://bugzilla.suse.com/1190180

Announcement ID: openSUSE-SU-2022:0061-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here