Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2018:2716-1 Important: Libzypp and Zypper Update Advisory

suse
Calendar Grey September 14, 2018
Dist Suse Esm H88
SUSE Security Update for libzypp and zypper encompasses critical improvements and remedies addressing several security flaws.
An update that solves two vulnerabilities and has 12 fixes is now available

Summary

This update for libzypp, zypper provides the following fixes: Update libzypp to version 16.17.20 Security issues fixed: - PackageProvider: Validate delta rpms before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) - PackageProvider: Validate downloaded rpm package signatures before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) Other bugs fixed: - lsof: use '-K i' if lsof supports it (bsc#1099847, bsc#1036304) - Handle http error 502 Bad Gateway in curl backend (bsc#1070851) - RepoManager: Explicitly request repo2solv to generate application pseudo packages. - libzypp-devel should not require cmake (bsc#1101349) - HardLocksFile: Prevent against empty commit without Target having been been loaded (bsc#1096803) - Avoid zombie tar processes (bsc#1076192) Update to zypper to version 1.13.45

References

#1036304 #1045735 #1049825 #1070851 #1076192

#1079334 #1088705 #1091624 #1092413 #1096803

#1099847 #1100028 #1101349 #1102429

Cross- CVE-2017-9269 CVE-2018-7685

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Enterprise Storage 4

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2017-9269.html

https://www.suse.com/security/cve/CVE-2018-7685.html

https://bugzilla.suse.com/1036304

https://bugzilla.suse.com/1045735

https://bugzilla.suse.com/1049825

https://bugzilla.suse.com/1070851

https://bugzilla.suse.com/1076192

https://bugzilla.suse.com/1079334

https://bugzilla.suse.com/1088705

https://bugzilla.suse.com/1091624

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2716-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here