Debian Security Advisory

DLA-611-1 jsch -- LTS security update

Date Reported:
05 Sep 2016
Affected Packages:
jsch
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-5725.
More information:

It was discovered that there was a path traversal vulnerability in jsch, a pure Java implementation of the SSH2 protocol.

For Debian 7 Wheezy, this issue has been fixed in jsch version 0.1.42-2+deb7u1.

We recommend that you upgrade your jsch packages.