Oval Definition:oval:org.opensuse.security:def:56142
Revision Date:2020-12-01Version:1
Title:Security update for libzypp, zypper (Important)
Description:

The Software Update Stack was updated to receive fixes and enhancements.

libzypp:

Security issues fixed: - CVE-2017-7435, CVE-2017-7436, CVE-2017-9269: Fix GPG check workflows, mainly for unsigned repositories and packages. (bsc#1045735, bsc#1038984)

Bug fixes: - Re-probe on refresh if the repository type changes. (bsc#1048315) - Propagate proper error code to DownloadProgressReport. (bsc#1047785) - Allow to trigger an appdata refresh unconditionally. (bsc#1009745) - Support custom repo variables defined in /etc/zypp/vars.d. - Adapt loop mounting of ISO images. (bsc#1038132, bsc#1033236) - Fix potential crash if repository has no baseurl. (bsc#1043218)

zypper:

- Adapt download callback to report and handle unsigned packages. (bsc#1038984) - Report missing/optional files as 'not found' rather than 'error'. (bsc#1047785) - Document support for custom repository variables defined in /etc/zypp/vars.d. - Emphasize that it depends on how fast PackageKit will respond to a 'quit' request sent if PK blocks package management.
Family:unixClass:patch
Status:Reference(s):1001487
1009745
1012183
1012759
1012852
1013543
1014271
1021417
1025013
1030575
1031481
1031756
1033236
1038132
1038984
1039496
1043218
1045735
1047785
1048315
1053153
1066295
1069708
1097108
1156402
872912
898031
899558
913001
917376
939460
945842
948516
948686
953110
953831
955382
958963
959094
960155
960305
961173
962765
964468
966220
968771
991667
CVE-2006-2607
CVE-2008-5519
CVE-2009-0946
CVE-2010-0424
CVE-2010-1674
CVE-2010-1675
CVE-2010-2497
CVE-2010-2805
CVE-2010-3053
CVE-2010-3054
CVE-2010-3311
CVE-2010-3814
CVE-2010-3855
CVE-2011-0226
CVE-2011-3256
CVE-2011-3439
CVE-2012-1126
CVE-2012-1127
CVE-2012-1128
CVE-2012-1129
CVE-2012-1130
CVE-2012-1131
CVE-2012-1132
CVE-2012-1133
CVE-2012-1134
CVE-2012-1135
CVE-2012-1136
CVE-2012-1137
CVE-2012-1138
CVE-2012-1139
CVE-2012-1140
CVE-2012-1141
CVE-2012-1142
CVE-2012-1143
CVE-2012-1144
CVE-2012-5668
CVE-2012-5669
CVE-2012-5670
CVE-2014-2240
CVE-2014-2241
CVE-2014-5044
CVE-2014-7204
CVE-2014-8111
CVE-2014-9656
CVE-2014-9657
CVE-2014-9658
CVE-2014-9659
CVE-2014-9660
CVE-2014-9661
CVE-2014-9662
CVE-2014-9663
CVE-2014-9664
CVE-2014-9665
CVE-2014-9666
CVE-2014-9667
CVE-2014-9668
CVE-2014-9669
CVE-2014-9670
CVE-2014-9671
CVE-2014-9672
CVE-2014-9673
CVE-2014-9674
CVE-2014-9675
CVE-2015-0240
CVE-2015-5276
CVE-2015-5313
CVE-2015-7552
CVE-2017-1000364
CVE-2017-10661
CVE-2017-13080
CVE-2017-13081
CVE-2017-16939
CVE-2017-7435
CVE-2017-7436
CVE-2017-9269
CVE-2018-10853
CVE-2019-2201
SUSE-SU-2015:0371-1
SUSE-SU-2016:0225-1
SUSE-SU-2016:0908-2
SUSE-SU-2016:0931-1
SUSE-SU-2017:1910-1
SUSE-SU-2017:2040-1
SUSE-SU-2017:3106-1
SUSE-SU-2017:3321-1
SUSE-SU-2018:2684-1
SUSE-SU-2019:2972-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.0 NonFree
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • bzip2-1.0.6-lp150.3 is installed
  • OR libbz2-1-1.0.6-lp150.3 is installed
  • OR libbz2-1-32bit-1.0.6-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.0 NonFree is installed
  • AND opera-54.0.2952.41-lp150.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libopenssl-1_0_0-devel-1.0.2p-lp151.5.3 is installed
  • OR libopenssl-1_0_0-devel-32bit-1.0.2p-lp151.5.3 is installed
  • OR libopenssl1_0_0-1.0.2p-lp151.5.3 is installed
  • OR libopenssl1_0_0-32bit-1.0.2p-lp151.5.3 is installed
  • OR libopenssl1_0_0-hmac-1.0.2p-lp151.5.3 is installed
  • OR libopenssl1_0_0-hmac-32bit-1.0.2p-lp151.5.3 is installed
  • OR openssl-1_0_0-1.0.2p-lp151.5.3 is installed
  • OR openssl-1_0_0-cavs-1.0.2p-lp151.5.3 is installed
  • OR openssl-1_0_0-doc-1.0.2p-lp151.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP3 is installed
  • AND Package Information
  • libldb1-3.6.3-0.56 is installed
  • OR libldb1-32bit-3.6.3-0.56 is installed
  • OR libsmbclient0-3.6.3-0.56 is installed
  • OR libsmbclient0-32bit-3.6.3-0.56 is installed
  • OR libtalloc2-3.6.3-0.56 is installed
  • OR libtalloc2-32bit-3.6.3-0.56 is installed
  • OR libtdb1-3.6.3-0.56 is installed
  • OR libtdb1-32bit-3.6.3-0.56 is installed
  • OR libtevent0-3.6.3-0.56 is installed
  • OR libtevent0-32bit-3.6.3-0.56 is installed
  • OR libwbclient0-3.6.3-0.56 is installed
  • OR libwbclient0-32bit-3.6.3-0.56 is installed
  • OR samba-3.6.3-0.56 is installed
  • OR samba-32bit-3.6.3-0.56 is installed
  • OR samba-client-3.6.3-0.56 is installed
  • OR samba-client-32bit-3.6.3-0.56 is installed
  • OR samba-doc-3.6.3-0.56 is installed
  • OR samba-krb-printing-3.6.3-0.56 is installed
  • OR samba-winbind-3.6.3-0.56 is installed
  • OR samba-winbind-32bit-3.6.3-0.56 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • gcc5-5.3.1+r233831-10 is installed
  • OR libgcc_s1-5.3.1+r233831-10 is installed
  • OR libgcc_s1-32bit-5.3.1+r233831-10 is installed
  • OR libgfortran3-5.3.1+r233831-10 is installed
  • OR libgfortran3-32bit-5.3.1+r233831-10 is installed
  • OR libgomp1-5.3.1+r233831-10 is installed
  • OR libgomp1-32bit-5.3.1+r233831-10 is installed
  • OR libquadmath0-5.3.1+r233831-10 is installed
  • OR libquadmath0-32bit-5.3.1+r233831-10 is installed
  • OR libstdc++6-5.3.1+r233831-10 is installed
  • OR libstdc++6-32bit-5.3.1+r233831-10 is installed
  • OR libstdc++6-locale-5.3.1+r233831-10 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND Package Information
  • libzypp-16.15.2-27.21 is installed
  • OR zypper-1.13.30-18.13 is installed
  • OR zypper-log-1.13.30-18.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • cpp48-4.8.5-24 is installed
  • OR gcc48-4.8.5-24 is installed
  • OR gcc48-32bit-4.8.5-24 is installed
  • OR gcc48-c++-4.8.5-24 is installed
  • OR gcc48-info-4.8.5-24 is installed
  • OR gcc48-locale-4.8.5-24 is installed
  • OR libasan0-4.8.5-24 is installed
  • OR libasan0-32bit-4.8.5-24 is installed
  • OR libstdc++48-devel-4.8.5-24 is installed
  • OR libstdc++48-devel-32bit-4.8.5-24 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • kgraft-patch-3_12_62-60_64_8-default-9-3 is installed
  • OR kgraft-patch-3_12_62-60_64_8-xen-9-3 is installed
  • OR kgraft-patch-SLE12-SP1_Update_8-9-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND apache2-mod_jk-1.2.40-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20180807-13.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • libsystemd0-228-150.66 is installed
  • OR libsystemd0-32bit-228-150.66 is installed
  • OR libudev-devel-228-150.66 is installed
  • OR libudev1-228-150.66 is installed
  • OR libudev1-32bit-228-150.66 is installed
  • OR systemd-228-150.66 is installed
  • OR systemd-32bit-228-150.66 is installed
  • OR systemd-bash-completion-228-150.66 is installed
  • OR systemd-sysvinit-228-150.66 is installed
  • OR udev-228-150.66 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_114-92_64-default-4-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_18-4-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libXrandr2-1.5.0-6 is installed
  • OR libXrandr2-32bit-1.5.0-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND perl-Archive-Zip-1.34-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND libksba8-1.3.0-23 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND python-XStatic-jquery-ui-1.11.0.1-2.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND squid-3.5.21-26.17 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • ardana-ansible-9.0+git.1587034359.a12678b-3.19 is installed
  • OR ardana-barbican-9.0+git.1583953599.cd723bb-3.10 is installed
  • OR ardana-cluster-9.0+git.1585653734.c1fe3b2-3.13 is installed
  • OR ardana-db-9.0+git.1586543314.6b6aa20-3.19 is installed
  • OR ardana-designate-9.0+git.1583445435.4bd1793-3.10 is installed
  • OR ardana-input-model-9.0+git.1584632190.9541c56-3.16 is installed
  • OR ardana-logging-9.0+git.1585929695.f35b591-3.10 is installed
  • OR ardana-monasca-9.0+git.1586769889.d43d736-3.16 is installed
  • OR ardana-mq-9.0+git.1586350749.a463fd2-3.13 is installed
  • OR ardana-neutron-9.0+git.1587667603.507fb50-3.19 is installed
  • OR ardana-octavia-9.0+git.1587486004.8e99c6b-3.16 is installed
  • OR ardana-osconfig-9.0+git.1586546715.dbd07ab-3.16 is installed
  • OR ardana-tempest-9.0+git.1587398456.b31cc4a-3.13 is installed
  • OR ardana-tls-9.0+git.1586301209.c9413b4-3.12 is installed
  • OR memcached-1.5.17-3.3 is installed
  • OR openstack-ceilometer-11.1.1~dev5-3.13 is installed
  • OR openstack-ceilometer-agent-central-11.1.1~dev5-3.13 is installed
  • OR openstack-ceilometer-agent-compute-11.1.1~dev5-3.13 is installed
  • OR openstack-ceilometer-agent-ipmi-11.1.1~dev5-3.13 is installed
  • OR openstack-ceilometer-agent-notification-11.1.1~dev5-3.13 is installed
  • OR openstack-ceilometer-polling-11.1.1~dev5-3.13 is installed
  • OR openstack-cinder-13.0.10~dev9-3.19 is installed
  • OR openstack-cinder-api-13.0.10~dev9-3.19 is installed
  • OR openstack-cinder-backup-13.0.10~dev9-3.19 is installed
  • OR openstack-cinder-scheduler-13.0.10~dev9-3.19 is installed
  • OR openstack-cinder-volume-13.0.10~dev9-3.19 is installed
  • OR openstack-designate-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-agent-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-api-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-central-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-producer-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-sink-7.0.1~dev25-3.16 is installed
  • OR openstack-designate-worker-7.0.1~dev25-3.16 is installed
  • OR openstack-heat-11.0.3~dev35-3.16 is installed
  • OR openstack-heat-api-11.0.3~dev35-3.16 is installed
  • OR openstack-heat-api-cfn-11.0.3~dev35-3.16 is installed
  • OR openstack-heat-engine-11.0.3~dev35-3.16 is installed
  • OR openstack-heat-plugin-heat_docker-11.0.3~dev35-3.16 is installed
  • OR openstack-ironic-11.1.5~dev3-3.16 is installed
  • OR openstack-ironic-api-11.1.5~dev3-3.16 is installed
  • OR openstack-ironic-conductor-11.1.5~dev3-3.16 is installed
  • OR openstack-ironic-image-9.0.0-3.6 is installed
  • OR openstack-ironic-image-x86_64-9.0.0-3.6 is installed
  • OR openstack-manila-7.4.2~dev4-4.21 is installed
  • OR openstack-manila-api-7.4.2~dev4-4.21 is installed
  • OR openstack-manila-data-7.4.2~dev4-4.21 is installed
  • OR openstack-manila-scheduler-7.4.2~dev4-4.21 is installed
  • OR openstack-manila-share-7.4.2~dev4-4.21 is installed
  • OR openstack-neutron-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-dhcp-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-ha-tool-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-l3-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-linuxbridge-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-macvtap-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-metadata-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-metering-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-openvswitch-agent-13.0.8~dev28-3.22 is installed
  • OR openstack-neutron-server-13.0.8~dev28-3.22 is installed
  • OR openstack-nova-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-api-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-cells-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-compute-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-conductor-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-console-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-novncproxy-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-placement-api-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-scheduler-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-serialproxy-18.3.1~dev17-3.22 is installed
  • OR openstack-nova-vncproxy-18.3.1~dev17-3.22 is installed
  • OR openstack-octavia-3.2.3~dev2-3.22 is installed
  • OR openstack-octavia-amphora-agent-3.2.3~dev2-3.22 is installed
  • OR openstack-octavia-amphora-image-0.1.3-7.9 is installed
  • OR openstack-octavia-amphora-image-x86_64-0.1.3-7.9 is installed
  • OR openstack-octavia-api-3.2.3~dev2-3.22 is installed
  • OR openstack-octavia-health-manager-3.2.3~dev2-3.22 is installed
  • OR openstack-octavia-housekeeping-3.2.3~dev2-3.22 is installed
  • OR openstack-octavia-worker-3.2.3~dev2-3.22 is installed
  • OR python-ceilometer-11.1.1~dev5-3.13 is installed
  • OR python-cinder-13.0.10~dev9-3.19 is installed
  • OR python-cinderclient-4.0.3-3.6 is installed
  • OR python-cinderclient-doc-4.0.3-3.6 is installed
  • OR python-designate-7.0.1~dev25-3.16 is installed
  • OR python-glanceclient-2.13.2-3.3 is installed
  • OR python-glanceclient-doc-2.13.2-3.3 is installed
  • OR python-heat-11.0.3~dev35-3.16 is installed
  • OR python-ironic-11.1.5~dev3-3.16 is installed
  • OR python-ironic-lib-2.14.3-3.6 is installed
  • OR python-ironicclient-2.5.4-4.10 is installed
  • OR python-ironicclient-doc-2.5.4-4.10 is installed
  • OR python-keystonemiddleware-5.2.2-17 is installed
  • OR python-manila-7.4.2~dev4-4.21 is installed
  • OR python-manila-tempest-plugin-0.1.0-3.6 is installed
  • OR python-neutron-13.0.8~dev28-3.22 is installed
  • OR python-nova-18.3.1~dev17-3.22 is installed
  • OR python-novaclient-11.0.1-3.3 is installed
  • OR python-novaclient-doc-11.0.1-3.3 is installed
  • OR python-octavia-3.2.3~dev2-3.22 is installed
  • OR python-octaviaclient-1.6.2-3.6 is installed
  • OR python-openstackclient-3.16.3-11 is installed
  • OR python-os-brick-2.5.10-3.9 is installed
  • OR python-os-brick-common-2.5.10-3.9 is installed
  • OR python-oslo.config-6.4.2-3.3 is installed
  • OR python-oslo.config-doc-6.4.2-3.3 is installed
  • OR python-oslo.rootwrap-5.14.2-3.3 is installed
  • OR python-oslo.utils-3.36.5-3.3 is installed
  • OR python-swiftclient-3.6.1-3.3 is installed
  • OR python-swiftclient-doc-3.6.1-3.3 is installed
  • OR python-watcherclient-2.1.1-3.3 is installed
  • OR release-notes-suse-openstack-cloud-9.20200319-3.18 is installed
  • OR venv-openstack-barbican-7.0.1~dev24-3.17 is installed
  • OR venv-openstack-barbican-x86_64-7.0.1~dev24-3.17 is installed
  • OR venv-openstack-cinder-13.0.10~dev9-3.17 is installed
  • OR venv-openstack-cinder-x86_64-13.0.10~dev9-3.17 is installed
  • OR venv-openstack-designate-7.0.1~dev25-3.17 is installed
  • OR venv-openstack-designate-x86_64-7.0.1~dev25-3.17 is installed
  • OR venv-openstack-glance-17.0.1~dev30-3.15 is installed
  • OR venv-openstack-glance-x86_64-17.0.1~dev30-3.15 is installed
  • OR venv-openstack-heat-11.0.3~dev35-3.17 is installed
  • OR venv-openstack-heat-x86_64-11.0.3~dev35-3.17 is installed
  • OR venv-openstack-horizon-14.1.1~dev1-4.16 is installed
  • OR venv-openstack-horizon-x86_64-14.1.1~dev1-4.16 is installed
  • OR venv-openstack-ironic-11.1.5~dev3-4.13 is installed
  • OR venv-openstack-ironic-x86_64-11.1.5~dev3-4.13 is installed
  • OR venv-openstack-keystone-14.1.1~dev36-3.17 is installed
  • OR venv-openstack-keystone-x86_64-14.1.1~dev36-3.17 is installed
  • OR venv-openstack-magnum-7.2.1~dev1-4.17 is installed
  • OR venv-openstack-magnum-x86_64-7.2.1~dev1-4.17 is installed
  • OR venv-openstack-manila-7.4.2~dev4-3.19 is installed
  • OR venv-openstack-manila-x86_64-7.4.2~dev4-3.19 is installed
  • OR venv-openstack-monasca-2.7.1~dev10-3.15 is installed
  • OR venv-openstack-monasca-ceilometer-1.8.2~dev3-3.17 is installed
  • OR venv-openstack-monasca-ceilometer-x86_64-1.8.2~dev3-3.17 is installed
  • OR venv-openstack-monasca-x86_64-2.7.1~dev10-3.15 is installed
  • OR venv-openstack-neutron-13.0.8~dev28-6.17 is installed
  • OR venv-openstack-neutron-x86_64-13.0.8~dev28-6.17 is installed
  • OR venv-openstack-nova-18.3.1~dev17-3.17 is installed
  • OR venv-openstack-nova-x86_64-18.3.1~dev17-3.17 is installed
  • OR venv-openstack-octavia-3.2.3~dev2-4.17 is installed
  • OR venv-openstack-octavia-x86_64-3.2.3~dev2-4.17 is installed
  • OR venv-openstack-sahara-9.0.2~dev15-3.17 is installed
  • OR venv-openstack-sahara-x86_64-9.0.2~dev15-3.17 is installed
  • OR venv-openstack-swift-2.19.2~dev48-2.12 is installed
  • OR venv-openstack-swift-x86_64-2.19.2~dev48-2.12 is installed
  • OR zookeeper-3.4.13-3.3 is installed
  • OR zookeeper-server-3.4.13-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND nodejs6-6.17.1-11.33 is installed
  • BACK