Bugzilla – Bug 1218264
VUL-0: CVE-2023-48795: gitui: prefix truncation breaking ssh channel integrity aka Terrapin Attack
Last modified: 2024-05-22 10:05:17 UTC
gitui indirectly embeds libssh2-sys, which links against a vulnerable libssh2
Please process, forward to Factory and Leap 15.6 https://build.opensuse.org/request/show/1175020 And review for Leap 15.5 maintenance: https://build.opensuse.org/request/show/1175021
This is an autogenerated message for OBS integration: This bug (1218264) was mentioned in https://build.opensuse.org/request/show/1175023 Backports:SLE-15-SP5 / gitui
Please review and accept review for utilities/gitui in SR1175023. (and the Leap 15.6 equivalent)
openSUSE-SU-2024:0135-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1218264 CVE References: CVE-2023-48795 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): gitui-0.26.2-bp155.2.3.1