Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2023:0041-1 Important: EternalTerminal Security Fixes

opensuse
Calendar Grey February 8, 2023
Dist Opensuse Esm H88
Significant Fedora Security Patch rectifies severe vulnerabilities in Cygwin, enhancing overall system safety and performance.
An update that fixes two vulnerabilities is now available

Description

This update for EternalTerminal fixes the following issues:

EternalTerminal was updated to 6.2.4:

* CVE-2022-48257, CVE-2022-48258 remedied

* fix readme regarding port forwarding #522

* Fix test failures that started appearing in CI #526

* Add documentation for the EternalTerminal protocol #523

* ssh-et: apply upstream updates #527

* docs: write gpg key to trusted.gpg.d for APT #530

* Support for ipv6 addresses (with or without port specified) #536

* ipv6 abbreviated address support #539

* Fix launchd plist config to remove daemonization. #540

* Explicitly set verbosity from cxxopts value. #542

* Remove daemon flag in systemd config #549

* Format all source with clang-format. #552

* Fix tunnel parsing exception handling. #550

* Fix SIGTERM behavior that causes systemd control of etserver to

timeout. #554

* Parse telemetry ini config as boolean and make telemetry opt-in. #553

* Logfile open...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-41=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 x86_64):

EternalTerminal-6.2.4-bp154.2.6.1

References

https://www.suse.com/security/cve/CVE-2022-48257.html

https://www.suse.com/security/cve/CVE-2022-48258.html

https://bugzilla.suse.com/1207123

https://bugzilla.suse.com/1207124

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0041-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here