This update for rpm fixes the following issues: This security vulnerability was fixed: - CVE-2017-7500: Fixed symlink attacks during RPM installation (bsc#943457) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-2018-1396=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1396=1 Package List: - SUSE Linux Enterprise Module for Development Tools 15 (aarch64 ppc64le s390x x86_64): rpm-build-4.14.1-10.3.1 rpm-build-debuginfo-4.14.1-10.3.1 rpm-debuginfo-4.14.1-10.3.1
#1094735 #1095148 #943457
Cross- CVE-2017-7500
Affected Products:
SUSE Linux Enterprise Module for Development Tools 15
SUSE Linux Enterprise Module for Basesystem 15
https://www.suse.com/security/cve/CVE-2017-7500.html
https://bugzilla.suse.com/1094735
https://bugzilla.suse.com/1095148
https://bugzilla.suse.com/943457
Get the latest Linux and open source security news straight to your inbox.