Bug 19296 - jsch new security issue CVE-2016-5725
Summary: jsch new security issue CVE-2016-5725
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/699682/
Whiteboard: advisory MGA5-32-OK
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-09-06 19:30 CEST by David Walser
Modified: 2016-09-21 22:39 CEST (History)
3 users (show)

See Also:
Source RPM: jsch-0.1.53-5.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-09-06 19:30:03 CEST
Debian-LTS has issued an advisory on September 5:
http://lwn.net/Alerts/699659/

Mageia 5 may also be affected.
Comment 1 David GEIGER 2016-09-06 22:15:42 CEST
Fixed for mga5 and freeze push requested for Cauldron.

CC: (none) => geiger.david68210

Comment 2 David Walser 2016-09-06 23:11:33 CEST
Thanks David!

Advisory:
========================

Updated jsch packages fix security vulnerability:

It was discovered that there was a path traversal vulnerability in jsch
(CVE-2016-5725).

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5725
http://lwn.net/Alerts/699659/
========================

Updated packages in core/updates_testing:
========================
jsch-0.1.51-4.1.mga5
jsch-javadoc-0.1.51-4.1.mga5
jsch-demo-0.1.51-4.1.mga5

from jsch-0.1.51-4.1.mga5.src.rpm

Version: Cauldron => 5
Assignee: mageia => qa-bugs

Comment 3 Dave Hodgins 2016-09-13 02:11:03 CEST
Got https://gist.githubusercontent.com/ymnk/2318108/raw/82819389a225265c2aa4ca11afc0b35e938607fe/Shell.java
to compile with "javac -cp /usr/share/java/jsch.jar Shell.java", but ran into
usual problems testing java programs, so validating based it the update installing
cleanly, and the example compiling ok.

Keywords: (none) => validated_update
Whiteboard: (none) => advisory MGA5-32-OK
CC: (none) => davidwhodgins, sysadmin-bugs

Comment 4 Mageia Robot 2016-09-21 22:39:23 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0311.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.