Libzip could be made to crash if it received specially crafted input.
Software Description:
- libsolv: A dependency solver using a satisfiablility algorithm
Details:
It was discovered that libsolv incorrectly handled certain malformed input. If a
user or automated system were tricked into opening a specially crafted file,
applications that rely on libsolv could be made to crash, resulting in a denial
of service.
The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: libsolv-tools 0.6.35-2ubuntu0.18.10.1 libsolv0 0.6.35-2ubuntu0.18.10.1 libsolvext0 0.6.35-2ubuntu0.18.10.1 After a standard system update you need to reboot your computer to make all the necessary changes.
https://ubuntu.com/security/notices/USN-3916-1
CVE-2018-20532, CVE-2018-20533, CVE-2018-20534
Get the latest Linux and open source security news straight to your inbox.