SUSE-SU-2017:0715-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20170715-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0715-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:0715-1
Upstream
Related
Published
2017-03-17T07:36:39Z
Modified
2026-02-04T04:18:36Z
Summary
Security update for jsch
Details

This update for jsch to version 0.1.54 fixes the following issues:

Security issues fixed:

  • CVE-2016-5725: recursive sftp get client-side windows path traversal (bsc#997542).

Bugfixes:

  • sftp-put may send the garbage data in some rare case.
  • fixed a deadlock bug in KnownHosts#getHostKey().
  • SftpProgressMonitor#init() was not invoked in sftp-put by using the output-stream.
  • KnownHosts#setKnownHosts() should accept the non-existing file.
  • excluding the user interaction time from the timeout value.
  • addressing SFTP slow file transfer speed with Titan FTP.
  • updating copyright messages; 2015 -> 2016
References

Affected packages

SUSE:Manager Server 3.0 / jsch

Package

Name
jsch
Purl
pkg:rpm/suse/jsch&distro=SUSE%20Manager%20Server%203.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.1.54-3.1

Ecosystem specific

{
    "binaries": [
        {
            "jsch": "0.1.54-3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0715-1.json"