Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

SUSE: 2019:1972-1 Moderate: libsolv, libzypp, zypper Security Fix

suse
Calendar Grey July 25, 2019
Dist Suse Esm H88
SUSE Security Patch: Revision for libsolv, libzypp, zypper addresses several vulnerabilities reported in SUSE-SU-2020:1234.
An update that solves three vulnerabilities and has 9 fixes is now available

Summary

This update for libsolv, libzypp and zypper fixes the following issues: libsolv was updated to version 0.6.36 fixes the following issues: Security issues fixed: - CVE-2018-20532: Fixed a NULL pointer dereference in testcase_read() (bsc#1120629). - CVE-2018-20533: Fixed a NULL pointer dereference in testcase_str2dep_complex() (bsc#1120630). - CVE-2018-20534: Fixed a NULL pointer dereference in pool_whatprovides() (bsc#1120631). Non-security issues fixed: - Made cleandeps jobs on patterns work (bsc#1137977). - Fixed an issue multiversion packages that obsolete their own name (bsc#1127155). - Keep consistent package name if there are multiple alternatives (bsc#1131823). libzypp received following fixes: - Fixes a bug where locking the kernel was not possible (bsc#1113296)

References

#1109893 #1110542 #1111319 #1112911 #1113296

#1120629 #1120630 #1120631 #1127155 #1131823

#1134226 #1137977

Cross- CVE-2018-20532 CVE-2018-20533 CVE-2018-20534

Affected Products:

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP5

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Desktop 12-SP5

SUSE Linux Enterprise Desktop 12-SP4

SUSE Enterprise Storage 5

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2018-20532.html

https://www.suse.com/security/cve/CVE-2018-20533.html

https://www.sus...

Read the Full Advisory

Announcement ID: SUSE-SU-2019:1972-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here