SUSE-RU-2015:1175-1

    Dashboard / Vulnerabilities / SUSE-RU-2015:1175-1

    SUSE-RU-2015:1175-1

    Published: 15 Jun 2015Last Modified: 2 May 2025
    Upstream:
    Aliases:

    Summary: Recommended update for Package Management Stack

    Details: This update provides fixes and enhancements for the Software Update Stack. gnome-packagekit: - Fix title of license agreement window. (bsc#927319) libsolv: - Rework splitprovides handling. (bnc#921332) - Add product:regflavor attribute. (bnc#896224) - Fix bug in reorder_dq_for_jobrules that could lead to crashes. (bnc#899907) - Fix bug in dislike_old_versions that could lead to a segfault. (bnc#922352) - Add manpages for the tools. libzypp: - Add configuration values for gpgcheck, repo_gpgcheck and pkg_gpgcheck to zypp.conf. (FATE#314603) - Support $releasever_major/$releasever_minor repo variables. (FATE#318354) - Support repo variable replacement in service url. - Support repo variable replacement in gpg url. - Add support for SHA224/384/512. - Don't execute scripts in /tmp or /var/tmp, as they could be mounted noexec for security reasons. (bnc#915928) - Let $ZYPP_REPO_RELEASEVER overwrite $releasever in .repo files. (bnc#911658) - Parse and offer productRegisterFlavor attribute. (bnc#896224) - Improve conflict message for locked packages. (bnc#828631) - Fix broken de-escaping in str::splitEscaped. (bnc#909772) - Filter PIDs running in a container. (bnc#909143) - Suppress informal license (no need to accept) upon update. (bnc#908976) - Adapt to gpg-2.1. (bnc#908135) - Call rpm with '--noglob'. (bnc#892431) - Fix URL path concatenation in MediaCurl. (bnc#901590) - Move doxygen html doc to libzypp-devel-doc. (bnc#901691) - Support parsing multiple baseurls from a repo file. (bnc#899510) - Suppress MediaChangeReport while testing multiple baseurls. (bnc#899510) - Fix handling local mirrorlist= files in .repo. (bnc#899510) - Prevent POODLE by talking TLS only. (bnc#903405) - Fix segmentation fault when dumping rpm header with epoch. (bnc#929483) - Handle repository aliases containing ']' correctly. (bnc#929528) - Avoid nested exception on user abort. (bnc#931601) - Fix SSL client certificate authentication via URL option ssl_clientcert/ssl_clientkey. (bnc#932393) libzypp-bindings: - Enforce Python 2.7 libzypp-bindings is not yet ready for Python 3. - Adapt to libzypp changes. zypper: - Implement and document GPG signature checking. (FATE#314603) - Enhance 'Digest verification failed' message and dialog. (FATE#315008) - Refresh plugin services on 'lr' 'ls -r' and 'ref'. (bnc#893294, FATE#318117) Repositories provided by a plugin service (SUSE Manager) must always be (auto-)refreshed to reflect server side changes immediately. - Allow repo:package to reinstall from a different repo. (bnc#725867) - Suppress MediaChangeReport while testing multiple baseurls. (bnc#899510) - A date limit must ignore newer patch candidates. (bnc#919709) - Notify about volatile changes to service repos. (bnc#916254) - Change column header from 'Login' to 'User'. (bnc#915461) - Fix wrong exit status using the --xmlout option. (bnc#914258) - Add new color/pkglistHighlightAttribute to zypper.conf. (bnc#914284) - New global option --releasever: Set the value of the $releasever variable in all .repo files. This can be used to switch to new distribution repositories when performing a distribution upgrade. (bnc#911658) - Clarify legacy warning. (bnc#911335) - Show new product:registerflavor attribute in 'zypper info'. (bnc#896224) - Enhance message text when skipping repos due to an error. (bnc#909244) - Fix additional spaces in zypper output and new colorization code. (bnc#908345) - Properly reset auto-retry counter. (bnc#906549) - Improve patch description in man page. (bnc#904737) - Warn about repositories with 'gpgcheck=0'. (bnc#848054) - Summary: quote names including spaces. (bnc#903675) - Warn if legacy CLI options are used. (bnc#899781) - Fix prompt returning undefined default value after wrong input. (bnc#925696) - Fix typo in man page. (bnc#923800) - Only use ANSI color codes on terminals. (bnc#925678) - Fix table sorting with option --sort-by-priority. (bnc#832519) - Clarify 'zypper lp --date' description. (bnc#929593) - Warn user that deleting a service repository is a volatile change. (bnc#929990) - Adapt Enterprise product detection, fixing display of package's support status. (bnc#933277) - Fix format of sizes in output. (bnc#897301) - Clarify comment in zypper.conf. (bnc#820693)

    References: https://www.suse.com/support/update/announcement//suse-ru-20151175-1/, https://bugzilla.suse.com/725867, https://bugzilla.suse.com/820693, https://bugzilla.suse.com/828631, https://bugzilla.suse.com/832519, https://bugzilla.suse.com/848054, https://bugzilla.suse.com/892431, https://bugzilla.suse.com/893294, https://bugzilla.suse.com/896224, https://bugzilla.suse.com/897301, https://bugzilla.suse.com/899510, https://bugzilla.suse.com/899603, https://bugzilla.suse.com/899781, https://bugzilla.suse.com/899907, https://bugzilla.suse.com/901590, https://bugzilla.suse.com/901691, https://bugzilla.suse.com/903405, https://bugzilla.suse.com/903675, https://bugzilla.suse.com/904737, https://bugzilla.suse.com/906549, https://bugzilla.suse.com/908135, https://bugzilla.suse.com/908345, https://bugzilla.suse.com/908976, https://bugzilla.suse.com/909143, https://bugzilla.suse.com/909244, https://bugzilla.suse.com/909772, https://bugzilla.suse.com/911335, https://bugzilla.suse.com/911658, https://bugzilla.suse.com/914258, https://bugzilla.suse.com/914284, https://bugzilla.suse.com/915461, https://bugzilla.suse.com/915928, https://bugzilla.suse.com/916254, https://bugzilla.suse.com/919709, https://bugzilla.suse.com/921332, https://bugzilla.suse.com/922352, https://bugzilla.suse.com/923800, https://bugzilla.suse.com/925678, https://bugzilla.suse.com/925696, https://bugzilla.suse.com/927319, https://bugzilla.suse.com/929483, https://bugzilla.suse.com/929528, https://bugzilla.suse.com/929593, https://bugzilla.suse.com/929990, https://bugzilla.suse.com/931601, https://bugzilla.suse.com/932393, https://bugzilla.suse.com/933277, https://www.suse.com/security/cve/CVE-2014-3566

    Affected packages

    Package

    Name: PackageKit

    Purl: pkg:rpm/suse/PackageKit&distro=SUSE%20Linux%20Enterprise%20Desktop%2012

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.8.16-11.15

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High