Oval Definition:oval:org.opensuse.security:def:50301
Revision Date:2020-12-01Version:1
Title:Security update for libzypp, zypper (Important)
Description:

This update for libzypp, zypper, libsolv provides the following fixes:

Security fixes in libzypp:

- CVE-2018-7685: PackageProvider: Validate RPMs before caching (bsc#1091624, bsc#1088705) - CVE-2017-9269: Be sure bad packages do not stay in the cache (bsc#1045735)

Changes in libzypp:

- Update to version 17.6.4 - Automatically fetch repository signing key from gpgkey url (bsc#1088037) - lsof: use '-K i' if lsof supports it (bsc#1099847,bsc#1036304) - Check for not imported keys after multi key import from rpmdb (bsc#1096217) - Flags: make it std=c++14 ready - Ignore /var, /tmp and /proc in zypper ps. (bsc#1096617) - Show GPGME version in log - Adapt to changes in libgpgme11-11.1.0 breaking the signature verification (bsc#1100427) - RepoInfo::provideKey: add report telling where we look for missing keys. - Support listing gpgkey URLs in repo files (bsc#1088037) - Add new report to request user approval for importing a package key - Handle http error 502 Bad Gateway in curl backend (bsc#1070851) - Add filesize check for downloads with known size (bsc#408814) - Removed superfluous space in translation (bsc#1102019) - Prevent the system from sleeping during a commit - RepoManager: Explicitly request repo2solv to generate application pseudo packages. - libzypp-devel should not require cmake (bsc#1101349) - Avoid zombies from ExternalProgram - Update ApiConfig - HardLocksFile: Prevent against empty commit without Target having been been loaded (bsc#1096803) - lsof: use '-K i' if lsof supports it (bsc#1099847) - Add filesize check for downloads with known size (bsc#408814) - Fix detection of metalink downloads and prevent aborting if a metalink file is larger than the expected data file. - Require libsolv-devel >= 0.6.35 during build (fixing bsc#1100095) - Make use of %license macro (bsc#1082318)

Security fix in zypper:

- CVE-2017-9269: Improve signature check callback messages (bsc#1045735)

Changes in zypper:

- Always set error status if any nr of unknown repositories are passed to lr and ref (bsc#1093103) - Notify user about unsupported rpm V3 keys in an old rpm database (bsc#1096217) - Detect read only filesystem on system modifying operations (fixes #199) - Use %license (bsc#1082318) - Handle repo aliases containing multiple ':' in the PackageArgs parser (bsc #1041178) - Fix broken display of detailed query results. - Fix broken search for items with a dash. (bsc#907538, bsc#1043166, bsc#1070770) - Disable repository operations when searching installed packages. (bsc#1084525) - Prevent nested calls to exit() if aborted by a signal. (bsc#1092413) - ansi.h: Prevent ESC sequence strings from going out of scope. (bsc#1092413) - Fix some translation errors. - Support listing gpgkey URLs in repo files (bsc#1088037) - Check for root privileges in zypper verify and si (bsc#1058515) - XML attribute `packages-to-change` added (bsc#1102429) - Add expert (allow-*) options to all installer commands (bsc#428822) - Sort search results by multiple columns (bsc#1066215) - man: Strengthen that `--config FILE' affects zypper.conf, not zypp.conf (bsc#1100028) - Set error status if repositories passed to lr and ref are not known (bsc#1093103) - Do not override table style in search - Fix out of bound read in MbsIterator - Add --supplements switch to search and info - Add setter functions for zypp cache related config values to ZConfig

Changes in libsolv:

- convert repo2solv.sh script into a binary tool - Make use of %license macro (bsc#1082318)
Family:unixClass:patch
Status:Reference(s):1036304
1041178
1043166
1044231
1045735
1046540
1050319
1050536
1050540
1051510
1051858
1055120
1056686
1058515
1060463
1065600
1065729
1066215
1066674
1067126
1067906
1070770
1070851
1071995
1076830
1079524
1082318
1083647
1084525
1084760
1084831
1086283
1086288
1088037
1088047
1088705
1091624
1092206
1092413
1093103
1094555
1094825
1095805
1096217
1096617
1096803
1098633
1099125
1099847
1100028
1100095
1100132
1100427
1101349
1102019
1102429
1102881
1103308
1103543
1103990
1103992
1104129
1104353
1104731
1104745
1105025
1105536
1106105
1106110
1106237
1106240
1106383
1106751
1106838
1107685
1108241
1108377
1108468
1108828
1108841
1108870
1109137
1109151
1109158
1109217
1109330
1109739
1109784
1109806
1109818
1109837
1109907
1109911
1109915
1109919
1109951
1110006
1110096
1110538
1110561
1110921
1111028
1111076
1111506
1111666
1111806
1111819
1111830
1111834
1111841
1111870
1111901
1111904
1111928
1111974
1111983
1112170
1112173
1112178
1112208
1112219
1112221
1112246
1112372
1112374
1112514
1112554
1112708
1112710
1112711
1112712
1112713
1112731
1112732
1112733
1112734
1112735
1112736
1112738
1112739
1112740
1112741
1112743
1112745
1112746
1112894
1112899
1112902
1112903
1112905
1112906
1112907
1113257
1113284
1113956
1114279
1114685
1117267
1119532
1119680
1120423
1122623
1124167
1124593
1126068
1126069
1127155
1127611
1128432
1128829
1128902
1128910
1128963
1130840
1131645
1132154
1132390
1133021
1133185
1133401
1133738
1134090
1134303
1134395
1135296
1135556
1135642
1136157
1136598
1136922
1136935
1137103
1137194
1137429
1137625
1137728
1137884
1137995
1137996
1137998
1137999
1138000
1138002
1138003
1138005
1138006
1138007
1138008
1138009
1138010
1138011
1138012
1138013
1138014
1138015
1138016
1138017
1138018
1138019
1138291
1138293
1138374
1138375
1138589
1138719
1139771
1139782
1139865
1140133
1140328
1140405
1140424
1140428
1140575
1140577
1140637
1140658
1140715
1140719
1140726
1140727
1140728
1140814
1141320
1141895
1143913
1144333
1146539
1149955
1150011
1153238
1156510
1157424
1158187
1159285
1160659
1161561
1161951
1162680
1162928
1162929
1162931
1164078
1164507
1165111
1165404
1165488
1165527
1165741
1165813
1165873
1165929
1165950
1165980
1165984
1165985
1166003
1166101
1166102
1166103
1166104
1166632
1166658
1166730
1166731
1166732
1166733
1166734
1166735
1169095
1169521
1169850
1169851
1169978
1171437
1172307
1172410
1172524
1173159
1173160
1173161
1173258
1173359
1174120
1175478
408814
428822
907538
CVE-2016-1000031
CVE-2017-16533
CVE-2017-18224
CVE-2017-9269
CVE-2018-16871
CVE-2018-18386
CVE-2018-18445
CVE-2018-19519
CVE-2018-20836
CVE-2018-5740
CVE-2018-5743
CVE-2018-5745
CVE-2018-7685
CVE-2019-10126
CVE-2019-10215
CVE-2019-10638
CVE-2019-10639
CVE-2019-11599
CVE-2019-12380
CVE-2019-12456
CVE-2019-12614
CVE-2019-12818
CVE-2019-12819
CVE-2019-14822
CVE-2019-16056
CVE-2019-16935
CVE-2019-19768
CVE-2019-3816
CVE-2019-3833
CVE-2019-6465
CVE-2019-7164
CVE-2019-7548
CVE-2019-9947
CVE-2020-10700
CVE-2020-10704
CVE-2020-10730
CVE-2020-10745
CVE-2020-10749
CVE-2020-10760
CVE-2020-12861
CVE-2020-12862
CVE-2020-12863
CVE-2020-12864
CVE-2020-12865
CVE-2020-12866
CVE-2020-12867
CVE-2020-14303
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2020-8903
CVE-2020-8907
CVE-2020-8933
CVE-2020-9383
SUSE-SU-2018:2690-1
SUSE-SU-2018:3593-1
SUSE-SU-2018:4131-1
SUSE-SU-2019:0654-1
SUSE-SU-2019:1212-2
SUSE-SU-2019:1407-1
SUSE-SU-2019:1829-1
SUSE-SU-2019:2253-1
SUSE-SU-2019:2387-1
SUSE-SU-2019:2743-1
SUSE-SU-2020:0836-1
SUSE-SU-2020:1934-1
SUSE-SU-2020:1957-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Module for Basesystem 15
SUSE Linux Enterprise Module for Live Patching 15
SUSE Linux Enterprise Module for Live Patching 15 SP1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Public Cloud 15
SUSE Linux Enterprise Module for Public Cloud 15 SP1
SUSE Linux Enterprise Module for Public Cloud 15 SP2
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Module for Server Applications 15 SP1
SUSE Linux Enterprise Module for Web Scripting 15
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 15-LTSS
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15 SP1
SUSE Linux Enterprise Workstation Extension 15 SP2
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • MozillaFirefox-10.0.7-0.3 is installed
  • OR MozillaFirefox-branding-SLED-7-0.6.7 is installed
  • OR MozillaFirefox-translations-10.0.7-0.3 is installed
  • OR libfreebl3-3.13.6-0.5 is installed
  • OR libfreebl3-32bit-3.13.6-0.5 is installed
  • OR mozilla-nspr-4.9.2-0.6 is installed
  • OR mozilla-nspr-32bit-4.9.2-0.6 is installed
  • OR mozilla-nss-3.13.6-0.5 is installed
  • OR mozilla-nss-32bit-3.13.6-0.5 is installed
  • OR mozilla-nss-tools-3.13.6-0.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND foomatic-filters-3.0.2-269.39 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND clamav-0.98.4-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • curl-7.37.0-15 is installed
  • OR libcurl4-7.37.0-15 is installed
  • OR libcurl4-32bit-7.37.0-15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • cups-filters-1.0.58-13 is installed
  • OR cups-filters-cups-browsed-1.0.58-13 is installed
  • OR cups-filters-foomatic-rip-1.0.58-13 is installed
  • OR cups-filters-ghostscript-1.0.58-13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • file-5.19-9 is installed
  • OR file-magic-5.19-9 is installed
  • OR libmagic1-5.19-9 is installed
  • OR libmagic1-32bit-5.19-9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • cron-4.2-58 is installed
  • OR cronie-1.4.11-58 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 is installed
  • AND Package Information
  • libsolv-0.6.35-3.5 is installed
  • OR libsolv-devel-0.6.35-3.5 is installed
  • OR libsolv-tools-0.6.35-3.5 is installed
  • OR libzypp-17.6.4-3.10 is installed
  • OR libzypp-devel-17.6.4-3.10 is installed
  • OR python-solv-0.6.35-3.5 is installed
  • OR zypper-1.14.10-3.7 is installed
  • OR zypper-log-1.14.10-3.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 is installed
  • AND Package Information
  • kernel-default-4.12.14-25.25 is installed
  • OR kernel-default-livepatch-4.12.14-25.25 is installed
  • OR kernel-livepatch-4_12_14-25_25-default-1-1.3 is installed
  • OR kernel-livepatch-SLE15_Update_7-1-1.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Live Patching 15 SP1 is installed
  • AND Package Information
  • kernel-default-4.12.14-197.37 is installed
  • OR kernel-default-livepatch-4.12.14-197.37 is installed
  • OR kernel-default-livepatch-devel-4.12.14-197.37 is installed
  • OR kernel-livepatch-4_12_14-197_37-default-1-3.3 is installed
  • OR kernel-livepatch-SLE15-SP1_Update_10-1-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 is installed
  • AND Package Information
  • bind-9.11.2-12.11 is installed
  • OR bind-lwresd-9.11.2-12.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
  • AND Package Information
  • jakarta-commons-fileupload-1.1.1-4.3 is installed
  • OR jakarta-commons-fileupload-javadoc-1.1.1-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • ctdb-pcp-pmda-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR ctdb-tests-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR ldb-2.0.12-3.3 is installed
  • OR libdcerpc-samr0-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR libsamba-policy0-python3-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR libsmbclient0-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR python3-ldb-32bit-2.0.12-3.3 is installed
  • OR samba-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR samba-ad-dc-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR samba-client-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR samba-doc-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR samba-libs-python3-32bit-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • OR samba-test-4.11.11+git.180.2cf3b203f07-4.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 is installed
  • AND Package Information
  • kernel-azure-4.12.14-5.33 is installed
  • OR kernel-azure-base-4.12.14-5.33 is installed
  • OR kernel-azure-devel-4.12.14-5.33 is installed
  • OR kernel-devel-azure-4.12.14-5.33 is installed
  • OR kernel-source-azure-4.12.14-5.33 is installed
  • OR kernel-syms-azure-4.12.14-5.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 SP1 is installed
  • AND Package Information
  • google-compute-engine-20190801-4.38 is installed
  • OR google-compute-engine-init-20190801-4.38 is installed
  • OR google-compute-engine-oslogin-20190801-4.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 15 SP2 is installed
  • AND Package Information
  • kernel-azure-5.3.18-18.18 is installed
  • OR kernel-azure-devel-5.3.18-18.18 is installed
  • OR kernel-devel-azure-5.3.18-18.18 is installed
  • OR kernel-source-azure-5.3.18-18.18 is installed
  • OR kernel-syms-azure-5.3.18-18.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 is installed
  • AND Package Information
  • xen-4.10.3_02-3.14 is installed
  • OR xen-devel-4.10.3_02-3.14 is installed
  • OR xen-tools-4.10.3_02-3.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP1 is installed
  • AND Package Information
  • freetds-1.1.36-3.3 is installed
  • OR libct4-1.1.36-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 15 is installed
  • AND Package Information
  • nodejs8-8.11.3-3.5 is installed
  • OR nodejs8-devel-8.11.3-3.5 is installed
  • OR nodejs8-docs-8.11.3-3.5 is installed
  • OR npm8-8.11.3-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • dovecot22-2.2.13-2 is installed
  • OR dovecot22-backend-mysql-2.2.13-2 is installed
  • OR dovecot22-backend-pgsql-2.2.13-2 is installed
  • OR dovecot22-backend-sqlite-2.2.13-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kernel-default-3.12.74-60.64.45 is installed
  • OR kernel-default-base-3.12.74-60.64.45 is installed
  • OR kernel-default-devel-3.12.74-60.64.45 is installed
  • OR kernel-default-man-3.12.74-60.64.45 is installed
  • OR kernel-devel-3.12.74-60.64.45 is installed
  • OR kernel-macros-3.12.74-60.64.45 is installed
  • OR kernel-source-3.12.74-60.64.45 is installed
  • OR kernel-syms-3.12.74-60.64.45 is installed
  • OR kernel-xen-3.12.74-60.64.45 is installed
  • OR kernel-xen-base-3.12.74-60.64.45 is installed
  • OR kernel-xen-devel-3.12.74-60.64.45 is installed
  • OR kgraft-patch-3_12_74-60_64_45-default-1-4 is installed
  • OR kgraft-patch-3_12_74-60_64_45-xen-1-4 is installed
  • OR kgraft-patch-SLE12-SP1_Update_16-1-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • accountsservice-0.6.42-14 is installed
  • OR accountsservice-lang-0.6.42-14 is installed
  • OR libaccountsservice0-0.6.42-14 is installed
  • OR typelib-1_0-AccountsService-1_0-0.6.42-14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • gnutls-3.2.15-18.6 is installed
  • OR libgnutls-openssl27-3.2.15-18.6 is installed
  • OR libgnutls28-3.2.15-18.6 is installed
  • OR libgnutls28-32bit-3.2.15-18.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • ntp-4.2.8p11-64.5 is installed
  • OR ntp-doc-4.2.8p11-64.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_90-92_45-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_14-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • MozillaFirefox-52.2.0esr-108 is installed
  • OR MozillaFirefox-translations-52.2.0esr-108 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_162-94_69-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_21-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libwireshark9-2.4.10-48.32 is installed
  • OR libwiretap7-2.4.10-48.32 is installed
  • OR libwscodecs1-2.4.10-48.32 is installed
  • OR libwsutil8-2.4.10-48.32 is installed
  • OR wireshark-2.4.10-48.32 is installed
  • OR wireshark-gtk-2.4.10-48.32 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15-LTSS is installed
  • AND Package Information
  • xen-4.10.4_16-3.41 is installed
  • OR xen-devel-4.10.4_16-3.41 is installed
  • OR xen-libs-4.10.4_16-3.41 is installed
  • OR xen-tools-4.10.4_16-3.41 is installed
  • OR xen-tools-domU-4.10.4_16-3.41 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • ghostscript-9.52-3.27 is installed
  • OR ghostscript-devel-9.52-3.27 is installed
  • OR ghostscript-x11-9.52-3.27 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • libopencv3_3-3.3.1-6.6 is installed
  • OR opencv-3.3.1-6.6 is installed
  • OR opencv-devel-3.3.1-6.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND Package Information
  • LibVNCServer-0.9.10-4.19 is installed
  • OR libvncclient0-0.9.10-4.19 is installed
  • OR libvncserver0-0.9.10-4.19 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND sudo-1.8.10p3-2.19 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND python-oslo.middleware-3.19.0-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND python-Twisted-15.2.1-9.5 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • libopenssl-devel-1.0.2j-60.55 is installed
  • OR libopenssl1_0_0-1.0.2j-60.55 is installed
  • OR libopenssl1_0_0-32bit-1.0.2j-60.55 is installed
  • OR libopenssl1_0_0-hmac-1.0.2j-60.55 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2j-60.55 is installed
  • OR openssl-1.0.2j-60.55 is installed
  • OR openssl-doc-1.0.2j-60.55 is installed
  • BACK