Oval Definition:oval:org.opensuse.security:def:202322742
Revision Date:2023-06-22Version:1
Title:CVE-2023-22742
Description:

libgit2 is a cross-platform, linkable library implementation of Git. When using an SSH remote with the optional libssh2 backend, libgit2 does not perform certificate checking by default. Prior versions of libgit2 require the caller to set the `certificate_check` field of libgit2's `git_remote_callbacks` structure - if a certificate check callback is not set, libgit2 does not perform any certificate checking. This means that by default - without configuring a certificate check callback, clients will not perform validation on the server SSH keys and may be subject to a man-in-the-middle attack. Users are encouraged to upgrade to v1.4.5 or v1.5.1. Users unable to upgrade should ensure that all relevant certificates are manually checked.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2023-22742
SUSE CVE-2023-22742
SUSE-SU-2023:1570-1
SUSE-SU-2023:1788-1
SUSE-SU-2023:1909-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND git-core is not affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • libgit2-1_3-1.3.0-150400.3.6.1 is installed
  • OR libgit2-devel-1.3.0-150400.3.6.1 is installed
  • OR git is not affected
  • OR git-arch is not affected
  • OR git-cvs is not affected
  • OR git-daemon is not affected
  • OR git-doc is not affected
  • OR git-email is not affected
  • OR git-gui is not affected
  • OR git-svn is not affected
  • OR git-web is not affected
  • OR gitk is not affected
  • OR perl-Git is not affected
  • BACK