Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2018:2716-2 Important: Libzypp and Zypper Security Fix

suse
Calendar Grey October 18, 2018
Dist Suse Esm H88
SUSE has issued a critical security patch for libzypp and zypper, introducing vital improvements in package verification protocols.
An update that solves two vulnerabilities and has 12 fixes is now available

Summary

This update for libzypp, zypper provides the following fixes: Update libzypp to version 16.17.20 Security issues fixed: - PackageProvider: Validate delta rpms before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) - PackageProvider: Validate downloaded rpm package signatures before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) Other bugs fixed: - lsof: use '-K i' if lsof supports it (bsc#1099847, bsc#1036304) - Handle http error 502 Bad Gateway in curl backend (bsc#1070851) - RepoManager: Explicitly request repo2solv to generate application pseudo packages. - libzypp-devel should not require cmake (bsc#1101349) - HardLocksFile: Prevent against empty commit without Target having been been loaded (bsc#1096803) - Avoid zombie tar processes (bsc#1076192) Update to zypper to version 1.13.45

References

#1036304 #1045735 #1049825 #1070851 #1076192

#1079334 #1088705 #1091624 #1092413 #1096803

#1099847 #1100028 #1101349 #1102429

Cross- CVE-2017-9269 CVE-2018-7685

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2017-9269.html

https://www.suse.com/security/cve/CVE-2018-7685.html

https://bugzilla.suse.com/1036304

https://bugzilla.suse.com/1045735

https://bugzilla.suse.com/1049825

https://bugzilla.suse.com/1070851

https://bugzilla.suse.com/1076192

https://bugzilla.suse.com/1079334

https://bugzilla.suse.com/1088705

https://bugzilla.suse.com/1091624

https://bugzilla.suse.com/1092413

https://bugzilla.suse.com/1096803

https://bugzilla.suse.com/1099847

https://bugzilla.suse.com/1100028

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2716-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here