{"id":"openSUSE-SU-2023:0041-1","summary":"Security update for EternalTerminal","details":"This update for EternalTerminal fixes the following issues:\n\nEternalTerminal was updated to 6.2.4:\n\n  * CVE-2022-48257, CVE-2022-48258 remedied\n  * fix readme regarding port forwarding #522\n  * Fix test failures that started appearing in CI #526\n  * Add documentation for the EternalTerminal protocol #523\n  * ssh-et: apply upstream updates #527\n  * docs: write gpg key to trusted.gpg.d for APT #530\n  * Support for ipv6 addresses (with or without port specified) #536\n  * ipv6 abbreviated address support #539\n  * Fix launchd plist config to remove daemonization. #540\n  * Explicitly set verbosity from cxxopts value. #542\n  * Remove daemon flag in systemd config #549\n  * Format all source with clang-format. #552\n  * Fix tunnel parsing exception handling. #550\n  * Fix SIGTERM behavior that causes systemd control of etserver to timeout. #554\n  * Parse telemetry ini config as boolean and make telemetry opt-in. #553\n  * Logfile open mode and permission plus location configurability. #556\n- boo#1207123 (CVE-2022-48257) Fix predictable logfile names in /tmp\n- boo#1207124 (CVE-2022-48258) Fix etserver and etclient have world-readable logfiles\n\n- Note: Upstream released 6.2.2 with fixes then 6.2.4 and later removed 6.2.2\n  and redid 6.2.4\n","modified":"2026-02-04T02:37:21.387654Z","published":"2023-02-08T02:02:05Z","related":["CVE-2022-48257","CVE-2022-48258"],"upstream":["CVE-2022-48257","CVE-2022-48258"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/T2VTENKRMSWIB6OVIPA263AB3ABXCRJT/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207123"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48257"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48258"}],"affected":[{"package":{"name":"EternalTerminal","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/EternalTerminal&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.4-bp154.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"EternalTerminal":"6.2.4-bp154.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0041-1.json"}},{"package":{"name":"EternalTerminal","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/EternalTerminal&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.4-bp154.2.6.1"}]}],"ecosystem_specific":{"binaries":[{"EternalTerminal":"6.2.4-bp154.2.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0041-1.json"}}],"schema_version":"1.7.3"}