SUSE-SU-2017:0715-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20170715-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0715-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:0715-1
Related
Published
2017-03-17T07:36:39Z
Modified
2017-03-17T07:36:39Z
Summary
Security update for jsch
Details

This update for jsch to version 0.1.54 fixes the following issues:

Security issues fixed: - CVE-2016-5725: recursive sftp get client-side windows path traversal (bsc#997542).

Bugfixes: - sftp-put may send the garbage data in some rare case. - fixed a deadlock bug in KnownHosts#getHostKey(). - SftpProgressMonitor#init() was not invoked in sftp-put by using the output-stream. - KnownHosts#setKnownHosts() should accept the non-existing file. - excluding the user interaction time from the timeout value. - addressing SFTP slow file transfer speed with Titan FTP. - updating copyright messages; 2015 -> 2016

References

Affected packages

SUSE:Manager Server 3.0 / jsch

Package

Name
jsch
Purl
pkg:rpm/suse/jsch&distro=SUSE%20Manager%20Server%203.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.54-3.1

Ecosystem specific

{
    "binaries": [
        {
            "jsch": "0.1.54-3.1"
        }
    ]
}