This update for libzypp, zypper fixes the following issues: libzypp security fixes: - PackageProvider: Validate delta rpms before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) - PackageProvider: Validate downloaded rpm package signatures before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) - Be sure bad packages do not stay in the cache (bsc#1045735, CVE-2017-9269) - Fix repo gpg check workflows, mainly for unsigned repos and packages (bsc#1045735, bsc#1038984, CVE-2017-7435, CVE-2017-7436, CVE-2017-9269) libzypp other changes/bugs fixed: - Update to version 14.45.17 - RepoInfo: add enum GpgCheck for convenient gpgcheck mode handling (bsc#1045735) - repo refresh: Re-probe if the repository type changes (bsc#1048315) - Use common workflow for downloading packages and srcpackages. This
#1036304 #1037210 #1038984 #1045735 #1048315
#1054088 #1070851 #1076192 #1079334 #1088705
#1091624 #1092413 #1096803 #1099847 #1100028
#1101349 #1102429
Cross- CVE-2017-7435 CVE-2017-7436 CVE-2017-9269
CVE-2018-7685
Affected Products:
SUSE Linux Enterprise Server 12-LTSS
https://www.suse.com/security/cve/CVE-2017-7435.html
https://www.suse.com/security/cve/CVE-2017-7436.html
https://www.suse.com/security/cve/CVE-2017-9269.html
https://www.suse.com/security/cve/CVE-2018-7685.html
https://bugzilla.suse.com/1036304
https://bugzilla.suse.com/1037210
https://bugzilla.suse.com/1038984
https://bugzilla.suse.com/1045735
https://bugzilla.suse.com/1048315
https://bugzilla.suse.com/1054088
https://bugzilla.suse.com/1070851
Get the latest Linux and open source security news straight to your inbox.