Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2018:2814-1 Important: libzypp, zypper Fixes, Critical Threat

suse
Calendar Grey September 24, 2018
Dist Suse Esm H88
SUSE Security Update: Security update for libzypp, zypper __________________________________________
An update that solves two vulnerabilities and has 11 fixes is now available

Summary

This update for libzypp, zypper fixes the following issues: Update libzypp to version 16.17.20: Security issues fixed: - PackageProvider: Validate deta rpms before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) - PackageProvider: Validate downloaded rpm package signatures before caching (bsc#1091624, bsc#1088705, CVE-2018-7685) Other bugs fixed: - lsof: use '-K i' if lsof supports it (bsc#1099847, bsc#1036304) - Handle http error 502 Bad Gateway in curl backend (bsc#1070851) - RepoManager: Explicitly request repo2solv to generate application pseudo packages. - libzypp-devel should not require cmake (bsc#1101349) - HardLocksFile: Prevent against empty commit without Target having been been loaded (bsc#1096803) - Avoid zombie tar processes (bsc#1076192) Update to zypper to version 1.13.45:

References

#1036304 #1045735 #1049825 #1070851 #1076192

#1088705 #1091624 #1092413 #1096803 #1099847

#1100028 #1101349 #1102429

Cross- CVE-2017-9269 CVE-2018-7685

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

SUSE CaaS Platform ALL

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2017-9269.html

https://www.suse.com/security/cve/CVE-2018-7685.html

https://bugzilla.suse.com/1036304

https://bugzilla.suse.com/1045735

https://bugzilla.suse.com/1049825

https://bugzilla.suse.com/1070851

https://bugzilla.suse.com/1076192

https://bugzilla.suse.com/1088705

https://bugzilla.suse.com/1091624

https://bugzilla.suse.com/1092413

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2814-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here