Bugzilla – Bug 1215509
VUL-0: CVE-2023-43618: croc: protocol requires a sender to provide its local IP addresses in cleartext
Last modified: 2023-09-20 09:15:06 UTC
CVE-2023-43618 An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-43618 https://www.cve.org/CVERecord?id=CVE-2023-43618 http://www.openwall.com/lists/oss-security/2023/09/08/2 https://github.com/schollz/croc/issues/597
Please submit to the following code streams: network croc openSUSE:Backports:SLE-15-SP6 croc