SUSE-SU-2021:0109-1
Dashboard / Vulnerabilities / SUSE-SU-2021:0109-1
SUSE-SU-2021:0109-1
Summary: Security update for libzypp, zypper
Details: This update for libzypp, zypper fixes the following issues: Update zypper to version 1.14.41 Update libzypp to 17.25.4 - CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583) - RepoManager: Force refresh if repo url has changed (bsc#1174016) - RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966) - RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427). - RpmDb: If no database exists use the _dbpath configured in rpm. Still makes sure a compat symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910) - Fixed update of gpg keys with elongated expire date (bsc#179222) - needreboot: remove udev from the list (bsc#1179083) - Fix lsof monitoring (bsc#1179909) yast-installation was updated to 4.2.48: - Do not cleanup the libzypp cache when the system has low memory, incomplete cache confuses libzypp later (bsc#1179415)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20210109-1/, https://bugzilla.suse.com/1050625, https://bugzilla.suse.com/1174016, https://bugzilla.suse.com/1177238, https://bugzilla.suse.com/1177275, https://bugzilla.suse.com/1177427, https://bugzilla.suse.com/1177583, https://bugzilla.suse.com/1178910, https://bugzilla.suse.com/1178966, https://bugzilla.suse.com/1179083, https://bugzilla.suse.com/1179222, https://bugzilla.suse.com/1179415, https://bugzilla.suse.com/1179909, https://www.suse.com/security/cve/CVE-2017-9271
Affected packages
Package
Name: libzypp
Purl: pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
