Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2022-24952: EternalTerminal: DoS triggered remotely by invalid sequence numbers | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Robert Frohl <rfrohl> |
Component: | Security | Assignee: | Security Team bot <security-team> |
Status: | IN_PROGRESS --- | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P3 - Medium | CC: | mvetter |
Version: | Leap 15.5 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/339928/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Robert Frohl
2022-08-16 12:14:33 UTC
already fixed in openSUSE:Factory but open for openSUSE:Backports:SLE-15-SP* I think a version upgrade would make sense here. SR#SR#997668 to Factory to include CVE/bugnumbers and adding the switch to choose gcc for Leap versions Update to 6.2.1: openSUSE_Backports_SLE-15-SP3_Update SR#997669 openSUSE_Backports_SLE-15-SP4_Update SR#997670 This is an autogenerated message for OBS integration: This bug (1202432) was mentioned in https://build.opensuse.org/request/show/997668 Factory / EternalTerminal https://build.opensuse.org/request/show/997669 Backports:SLE-15-SP3 / EternalTerminal https://build.opensuse.org/request/show/997670 Backports:SLE-15-SP4 / EternalTerminal openSUSE-SU-2022:10187-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1202432,1202433,1202434,1202435 CVE References: CVE-2022-24949,CVE-2022-24950,CVE-2022-24951,CVE-2022-24952 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): EternalTerminal-6.2.1-bp153.2.3.1 openSUSE-SU-2022:10185-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1202432,1202433,1202434,1202435 CVE References: CVE-2022-24949,CVE-2022-24950,CVE-2022-24951,CVE-2022-24952 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): EternalTerminal-6.2.1-bp154.2.3.1 |