Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

SUSE: 2024:0057-1 important: eclipse-jgit jsch file overwrite

suse
Calendar Grey January 8, 2024
Dist Suse Esm H88
SUSE announces a crucial security update for eclipse-jgit and jsch addressing a critical flaw.
* bsc#1209646 * bsc#1211955 * bsc#1215298 * jsc#PED-6376 * jsc#PED-6377

Summary

## This update for eclipse-jgit, jsch fixes the following issues: Security fix: \- CVE-2023-4759: Fixed an arbitrary file overwrite which might have occurred with a specially crafted git repository and a case-insensitive filesystem. (bsc#1215298) Other fixes: jsch was updated to version 0.2.9: \- Added support for various algorithms \- Migrated from `com.jcraft:jsch` to `com.github.mwiede:jsch` fork (bsc#1211955): * Alias to the old artifact since the new one is drop-in replacement * Keep the old OSGi bundle symbolic name to avoid extensive patching of eclipse stack \- Updated to version 0.2.9: * For the full list of changes please consult the upstream changelogs below for each version updated: \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.9 \+

References

* bsc#1209646

* bsc#1211955

* bsc#1215298

* jsc#PED-6376

* jsc#PED-6377

Cross-

* CVE-2023-4759

CVSS scores:

* CVE-2023-4759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2023-4759 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Development Tools Module 15-SP4

* Development Tools Module 15-SP5

* openSUSE Leap 15.4

* openSUSE Leap 15.5

* SUSE Enterprise Storage 7.1

* SUSE Linux Enterprise Desktop 15 SP4

* SUSE Linux Enterprise Desktop 15 SP5

* SUSE Linux Enterprise High Performance Computing 15 SP2

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

* SUSE Linux Enterprise High Performance Computing 15 SP3

* SUSE Linux Enterprise High Performance Computing 15 SP4

* SUSE Linux Enterprise High Performance Computing 15 SP5

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0057-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here