Bugzilla – Bug 1202432
VUL-0: CVE-2022-24952: EternalTerminal: DoS triggered remotely by invalid sequence numbers
Last modified: 2022-11-02 17:28:51 UTC
CVE-2022-24952 Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered remotely by an invalid sequence number and a local bug triggered by invalid input sent directly to the IPC socket. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-24952 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24952 https://github.com/MisterTea/EternalTerminal/releases/tag/et-v6.2.0 https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-8cw3-6r98-g7cw
already fixed in openSUSE:Factory but open for openSUSE:Backports:SLE-15-SP*
I think a version upgrade would make sense here. SR#SR#997668 to Factory to include CVE/bugnumbers and adding the switch to choose gcc for Leap versions Update to 6.2.1: openSUSE_Backports_SLE-15-SP3_Update SR#997669 openSUSE_Backports_SLE-15-SP4_Update SR#997670
This is an autogenerated message for OBS integration: This bug (1202432) was mentioned in https://build.opensuse.org/request/show/997668 Factory / EternalTerminal https://build.opensuse.org/request/show/997669 Backports:SLE-15-SP3 / EternalTerminal https://build.opensuse.org/request/show/997670 Backports:SLE-15-SP4 / EternalTerminal
openSUSE-SU-2022:10187-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1202432,1202433,1202434,1202435 CVE References: CVE-2022-24949,CVE-2022-24950,CVE-2022-24951,CVE-2022-24952 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): EternalTerminal-6.2.1-bp153.2.3.1
openSUSE-SU-2022:10185-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1202432,1202433,1202434,1202435 CVE References: CVE-2022-24949,CVE-2022-24950,CVE-2022-24951,CVE-2022-24952 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): EternalTerminal-6.2.1-bp154.2.3.1