SUSE-SU-2019:1972-1
Dashboard / Vulnerabilities / SUSE-SU-2019:1972-1
SUSE-SU-2019:1972-1
Summary: Security update for libsolv, libzypp, zypper
Details: This update for libsolv, libzypp and zypper fixes the following issues: libsolv was updated to version 0.6.36 fixes the following issues: Security issues fixed: - CVE-2018-20532: Fixed a NULL pointer dereference in testcase_read() (bsc#1120629). - CVE-2018-20533: Fixed a NULL pointer dereference in testcase_str2dep_complex() (bsc#1120630). - CVE-2018-20534: Fixed a NULL pointer dereference in pool_whatprovides() (bsc#1120631). Non-security issues fixed: - Made cleandeps jobs on patterns work (bsc#1137977). - Fixed an issue multiversion packages that obsolete their own name (bsc#1127155). - Keep consistent package name if there are multiple alternatives (bsc#1131823). libzypp received following fixes: - Fixes a bug where locking the kernel was not possible (bsc#1113296) zypper received following fixes: - Fixes a bug where the wrong exit code was set when refreshing repos if --root was used (bsc#1134226) - Improved the displaying of locks (bsc#1112911) - Fixes an issue where `https` repository urls caused an error prompt to appear twice (bsc#1110542) - zypper will now always warn when no repositories are defined (bsc#1109893)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20191972-1/, https://bugzilla.suse.com/1109893, https://bugzilla.suse.com/1110542, https://bugzilla.suse.com/1111319, https://bugzilla.suse.com/1112911, https://bugzilla.suse.com/1113296, https://bugzilla.suse.com/1120629, https://bugzilla.suse.com/1120630, https://bugzilla.suse.com/1120631, https://bugzilla.suse.com/1127155, https://bugzilla.suse.com/1131823, https://bugzilla.suse.com/1134226, https://bugzilla.suse.com/1137977, https://www.suse.com/security/cve/CVE-2018-20532, https://www.suse.com/security/cve/CVE-2018-20533, https://www.suse.com/security/cve/CVE-2018-20534
Affected packages
Package
Name: libsolv
Purl: pkg:rpm/suse/libsolv&distro=SUSE%20OpenStack%20Cloud%208
Affected ranges
Type: ECOSYSTEM
Events:
