Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

openSUSE: 2022:10187-1 Important: EternalTerminal Threats Fixed

opensuse
Calendar Grey November 2, 2022
Dist Opensuse Esm H88
Crucial security patch released for openSUSE addressing several flaws in EternalTerminal. Discover insights on significant risks.
An update that fixes four vulnerabilities is now available

Description

This update for EternalTerminal fixes the following issues:

Update to 6.2.1:

* CVE-2022-24949: Fixed race condition allows local attacker to hijack IPC

socket (boo#1202435)

* CVE-2022-24950: Fixed privilege escalation to root (boo#1202434)

* CVE-2022-24951: Fixed DoS triggered remotely by invalid sequence numbers (boo#1202433)

* CVE-2022-24952: Fixed race condition allows authenticated attacker to

hijack other users' SSH authorization socket (boo#1202432)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP3:

zypper in -t patch openSUSE-2022-10187=1

Package List

- openSUSE Backports SLE-15-SP3 (aarch64 x86_64):

EternalTerminal-6.2.1-bp153.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-24949.html

https://www.suse.com/security/cve/CVE-2022-24950.html

https://www.suse.com/security/cve/CVE-2022-24951.html

https://www.suse.com/security/cve/CVE-2022-24952.html

https://bugzilla.suse.com/1202432

https://bugzilla.suse.com/1202433

https://bugzilla.suse.com/1202434

https://bugzilla.suse.com/1202435

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10187-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here