Oval Definition:oval:org.opensuse.security:def:126299
Revision Date:2019-07-25Version:1
Title:Security update for libsolv, libzypp, zypper (Moderate)
Description:

This update for libsolv, libzypp and zypper fixes the following issues:

libsolv was updated to version 0.6.36 fixes the following issues:

Security issues fixed:

- CVE-2018-20532: Fixed a NULL pointer dereference in testcase_read() (bsc#1120629). - CVE-2018-20533: Fixed a NULL pointer dereference in testcase_str2dep_complex() (bsc#1120630). - CVE-2018-20534: Fixed a NULL pointer dereference in pool_whatprovides() (bsc#1120631).

Non-security issues fixed:

- Made cleandeps jobs on patterns work (bsc#1137977). - Fixed an issue multiversion packages that obsolete their own name (bsc#1127155). - Keep consistent package name if there are multiple alternatives (bsc#1131823).

libzypp received following fixes:

- Fixes a bug where locking the kernel was not possible (bsc#1113296)

zypper received following fixes:

- Fixes a bug where the wrong exit code was set when refreshing repos if --root was used (bsc#1134226) - Improved the displaying of locks (bsc#1112911) - Fixes an issue where `https` repository urls caused an error prompt to appear twice (bsc#1110542) - zypper will now always warn when no repositories are defined (bsc#1109893)
Family:unixClass:patch
Status:Reference(s):1109893
1110542
1111319
1112911
1113296
1120629
1120630
1120631
1127155
1131823
1134226
1137977
CVE-2018-20532
CVE-2018-20533
CVE-2018-20534
SUSE-SU-2019:1972-1
Platform(s):SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP4
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND
  • libsolv-tools-0.6.36-2.16.2 is installed
  • OR libzypp-16.20.0-2.39.4 is installed
  • OR perl-solv-0.6.36-2.16.2 is installed
  • OR python-solv-0.6.36-2.16.2 is installed
  • OR zypper-1.13.51-21.26.4 is installed
  • OR zypper-log-1.13.51-21.26.4 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND
  • libsolv-tools-0.6.36-2.16.2 is installed
  • OR libzypp-16.20.0-2.39.4 is installed
  • OR perl-solv-0.6.36-2.16.2 is installed
  • OR python-solv-0.6.36-2.16.2 is installed
  • OR zypper-1.13.51-21.26.4 is installed
  • OR zypper-log-1.13.51-21.26.4 is installed
  • BACK