MGASA-2020-0245 - Updated libzypp packages fix security vulnerability

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0245.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-18900

Libzypp from mageia 7 is affected by a security issue.
This update fixes this.


Incorrect Default Permissions vulnerability in libzypp allowed local
attackers to read a cookie store used by libzypp, exposing private
cookies.

References:
- https://bugs.mageia.org/show_bug.cgi?id=26068
- https://bugzilla.suse.com/show_bug.cgi?id=1158763
- https://github.com/openSUSE/libzypp/pull/196
- https://github.com/openSUSE/libzypp/commit/ea50981352bb5c7ab48663edaeb2df1ddd66953e
- https://github.com/openSUSE/libzypp/commit/508b1201f23b44ee90dee6dbbeb3ac5f8bd4c089
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18900

SRPMS:
- 7/core/libzypp-17.9.0-1.1.mga7