## This update for eclipse-jgit, jsch fixes the following issues: Security fix: \- CVE-2023-4759: Fixed an arbitrary file overwrite which might have occurred with a specially crafted git repository and a case-insensitive filesystem. (bsc#1215298) Other fixes: jsch was updated to version 0.2.9: \- Added support for various algorithms \- Migrated from `com.jcraft:jsch` to `com.github.mwiede:jsch` fork (bsc#1211955): * Alias to the old artifact since the new one is drop-in replacement * Keep the old OSGi bundle symbolic name to avoid extensive patching of eclipse stack \- Updated to version 0.2.9: * For the full list of changes please consult the upstream changelogs below for each version updated: \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.9 \+
* bsc#1209646
* bsc#1211955
* bsc#1215298
* jsc#PED-6376
* jsc#PED-6377
Cross-
* CVE-2023-4759
CVSS scores:
* CVE-2023-4759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-4759 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Development Tools Module 15-SP4
* Development Tools Module 15-SP5
* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Enterprise Storage 7.1
* SUSE Linux Enterprise Desktop 15 SP4
* SUSE Linux Enterprise Desktop 15 SP5
* SUSE Linux Enterprise High Performance Computing 15 SP2
* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
* SUSE Linux Enterprise High Performance Computing 15 SP3
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
Get the latest Linux and open source security news straight to your inbox.