Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia 7 MGASA-2020-0245 Critical: Libzypp Incorrect Permissions

mageia
Calendar Grey June 10, 2020
Dist Mageia Esm H88
MGASA-2020-0246 resolves a vulnerability in libzypp, improving the overall safety of Mageia 7.
Libzypp from mageia 7 is affected by a security issue

Summary

Libzypp from mageia 7 is affected by a security issue. This update fixes this.

Incorrect Default Permissions vulnerability in libzypp allowed local attackers to read a cookie store used by libzypp, exposing private cookies.

References

- https://bugs.mageia.org/show_bug.cgi?id=26068

- https://bugzilla.suse.com/show_bug.cgi?id=1158763

- https://github.com/openSUSE/libzypp/pull/196

- https://github.com/openSUSE/libzypp/commit/ea50981352bb5c7ab48663edaeb2df1ddd66953e

- https://github.com/openSUSE/libzypp/commit/508b1201f23b44ee90dee6dbbeb3ac5f8bd4c089

- https://www.cve.org/CVERecord?id=CVE-2019-18900

Resolution

SRPMS

- 7/core/libzypp-17.9.0-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0245.html
Type: security
CVE: CVE-2019-18900

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here