SUSE-SU-2021:2180-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2180-1
SUSE-SU-2021:2180-1
Summary: Security update for libsolv
Details: This update for libsolv fixes the following issues: Security issues fixed: - CVE-2019-20387: Fixed heap-buffer-overflow in repodata_schema2id (bsc#1161510) - CVE-2021-3200: testcase_read: error out if repos are added or the system is changed too late (bsc#1186229) Other issues fixed: - backport support for blacklisted packages to support ptf packages and retracted patches - fix ruleinfo of complex dependencies returning the wrong origin - fix SOLVER_FLAG_FOCUS_BEST updateing packages without reason - fix add_complex_recommends() selecting conflicted packages in rare cases - fix potential segfault in resolve_jobrules - fix solv_zchunk decoding error if large chunks are used
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212180-1/, https://bugzilla.suse.com/1161510, https://bugzilla.suse.com/1186229, https://www.suse.com/security/cve/CVE-2019-20387, https://www.suse.com/security/cve/CVE-2021-3200
Affected packages
Package
Name: libsolv
Purl: pkg:rpm/suse/libsolv&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
