Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2019:2742-1

Опубликовано: 22 окт. 2019
Источник: suse-cvrf

Описание

Recommended update for libzypp, zypper, libsolv and PackageKit

This update for libzypp, zypper, libsolv and PackageKit fixes the following issues:

Security issues fixed in libsolv:

  • CVE-2018-20532: Fixed NULL pointer dereference at ext/testcase.c (function testcase_read) (bsc#1120629).
  • CVE-2018-20533: Fixed NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a (bsc#1120630).
  • CVE-2018-20534: Fixed illegal address access at src/pool.h (function pool_whatprovides) in libsolv.a (bsc#1120631).

Other issues addressed in libsolv:

  • Fixed an issue where libsolv failed to build against swig 4.0 by updating the version to 0.7.5 (bsc#1135749).
  • Fixed an issue with the package name (bsc#1131823).
  • repo_add_rpmdb: do not copy bad solvables from the old solv file
  • Fixed an issue with cleandeps updates in which all packages were not updated
  • Experimental DISTTYPE_CONDA and REL_CONDA support
  • Fixed cleandeps jobs when using patterns (bsc#1137977)
  • Fixed favorq leaking between solver runs if the solver is reused
  • Fixed SOLVER_FLAG_FOCUS_BEST updateing packages without reason
  • Be more correct with multiversion packages that obsolete their own name (bnc#1127155)
  • Fix repository priority handling for multiversion packages
  • Make code compatible with swig 4.0, remove obj0 instances
  • repo2solv: support zchunk compressed data
  • Remove NO_BRP_STRIP_DEBUG=true as brp-15-strip-debug will not strip debug info for archives

Issues fixed in libzypp:

  • Fix empty metalink downloads if filesize is unknown (bsc#1153557)
  • Recognize riscv64 as architecture
  • Fix installation of new header file (fixes #185)
  • zypp.conf: Introduce solver.focus to define the resolvers general attitude when resolving jobs. (bsc#1146415)
  • New container detection algorithm for zypper ps (bsc#1146947)
  • Fix leaking filedescriptors in MediaCurl. (bsc#1116995)
  • Run file conflict check on dry-run. (bsc#1140039)
  • Do not remove orphan products if the .prod file is owned by a package. (bsc#1139795)
  • Rephrase file conflict check summary. (bsc#1140039)
  • Fix bash completions option detection. (bsc#1049825)
  • Fixes a bug where zypper exited on SIGPIPE when downloading packages (bsc#1145521)
  • Fixes an issue where zypper exited with a segmentation fault when updating via YaST2 (bsc#1146027)
  • PublicKey::algoName: supply key algorithm and length

Issues fixed in zypper:

  • Update to version 1.14.30
  • Ignore SIGPIPE while STDOUT/STDERR are OK (bsc#1145521)
  • Dump stacktrace on SIGPIPE (bsc#1145521)
  • info: The requested info must be shown in QUIET mode (fixes #287)
  • Fix local/remote url classification.
  • Rephrase file conflict check summary (bsc#1140039)
  • Fix bash completions option detection (bsc#1049825)
  • man: split '--with[out]' like options to ease searching.
  • Unhided 'ps' command in help
  • Added option to show more conflict information
  • Rephrased zypper ps hint (bsc#859480)
  • Fixed repo refresh not returning 106-ZYPPER_EXIT_INF_REPOS_SKIPPED if --root is used (bsc#1134226)
  • Fixed unknown package handling in zypper install (bsc#1127608)
  • Re-show progress bar after pressing retry upon install error (bsc#1131113)

Issues fixed in PackageKit:

  • Port the cron configuration variables to the systemd timer script, and add -sendwait parameter to mail in the script(bsc#1130306).

Список пакетов

Container caasp/v4/389-ds:1.4.2
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/busybox:1.34.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/caasp-dex:2.16.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cert-exporter:2.3.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cilium-etcd-operator:2.0.5
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cilium-init:1.5.3
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cilium-operator:1.6.6
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cilium:1.6.6
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/cloud-provider-openstack:1.15.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/configmap-reload:0.3.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/coredns:1.6.7
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/curl:7.60.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/etcd:3.4.13
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/gangway:3.1.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/grafana:7.5.12
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/helm-tiller:2.16.12
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/hyperkube:v1.17.17
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/k8s-sidecar:0.1.75
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/kube-state-metrics:1.9.3
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/kubernetes-client:1.17.17
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/kucero:1.3.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/kured:1.3.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/metrics-server:0.3.6
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/prometheus-alertmanager:0.16.2
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/prometheus-node-exporter:1.1.2
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/prometheus-pushgateway:0.6.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/prometheus-server:2.7.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/rsyslog:8.39.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/skuba-tooling:0.1.0
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/test-update:beta
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/velero-plugin-for-aws:1.0.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/velero-plugin-for-gcp:1.0.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/velero-plugin-for-microsoft-azure:1.0.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/velero-restic-restore-helper:1.3.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container caasp/v4/velero:1.3.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container ses/6/cephcsi/cephcsi:latest
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container ses/6/rook/ceph:latest
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Container suse/sle15:15.1
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Image SLES15-SP1-Azure-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Azure-HPC-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-CAP-Deployment-BYOS-EC2-HVM
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
zypper-1.14.30-3.7.2
Image SLES15-SP1-CAP-Deployment-BYOS-GCE
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
zypper-1.14.30-3.7.2
Image SLES15-SP1-CHOST-BYOS-Azure
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Image SLES15-SP1-CHOST-BYOS-EC2
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Image SLES15-SP1-CHOST-BYOS-GCE
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
zypper-1.14.30-3.7.2
Image SLES15-SP1-EC2-HPC-HVM-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-EC2-HVM-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-GCE-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Proxy
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Proxy
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Proxy
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Server
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-OCI-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-Azure
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-Azure-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-EC2-HVM
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-EC2-HVM-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-GCE
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-GCE-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAP-OCI-BYOS
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg9-2.48.9-7.3.5
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAPCAL-Azure
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAPCAL-EC2-HVM
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
Image SLES15-SP1-SAPCAL-GCE
libsolv-tools-0.7.6-3.7.2
libzypp-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
libsolv-devel-0.7.6-3.7.2
libsolv-tools-0.7.6-3.7.2
libyui-ncurses-pkg-devel-2.48.9-7.3.5
libyui-ncurses-pkg-doc-2.48.9-7.3.3
libyui-ncurses-pkg9-2.48.9-7.3.5
libyui-qt-pkg-doc-2.45.27-3.3.3
libyui-qt-pkg9-2.45.27-3.3.5
libzypp-17.15.0-3.9.1
libzypp-devel-17.15.0-3.9.1
python3-solv-0.7.6-3.7.2
yast2-pkg-bindings-4.1.2-3.3.5
zypper-1.14.30-3.7.2
zypper-log-1.14.30-3.7.2
zypper-needs-restarting-1.14.30-3.7.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP1
PackageKit-1.1.10-12.3.5
PackageKit-backend-zypp-1.1.10-12.3.5
PackageKit-devel-1.1.10-12.3.5
PackageKit-lang-1.1.10-12.3.5
libpackagekit-glib2-18-1.1.10-12.3.5
libpackagekit-glib2-devel-1.1.10-12.3.5
libyui-qt-pkg-devel-2.45.27-3.3.5
typelib-1_0-PackageKitGlib-1_0-1.1.10-12.3.5
SUSE Linux Enterprise Module for Development Tools 15 SP1
perl-solv-0.7.6-3.7.2
ruby-solv-0.7.6-3.7.2
SUSE Linux Enterprise Module for Package Hub 15 SP1
python-solv-0.7.6-3.7.2
SUSE Linux Enterprise Workstation Extension 15 SP1
PackageKit-gstreamer-plugin-1.1.10-12.3.5
PackageKit-gtk3-module-1.1.10-12.3.5

Описание

There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.


Затронутые продукты
Container caasp/v4/389-ds:1.4.2:libsolv-tools-0.7.6-3.7.2
Container caasp/v4/389-ds:1.4.2:libzypp-17.15.0-3.9.1
Container caasp/v4/389-ds:1.4.2:zypper-1.14.30-3.7.2
Container caasp/v4/busybox:1.34.1:libsolv-tools-0.7.6-3.7.2

Ссылки

Описание

There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.


Затронутые продукты
Container caasp/v4/389-ds:1.4.2:libsolv-tools-0.7.6-3.7.2
Container caasp/v4/389-ds:1.4.2:libzypp-17.15.0-3.9.1
Container caasp/v4/389-ds:1.4.2:zypper-1.14.30-3.7.2
Container caasp/v4/busybox:1.34.1:libsolv-tools-0.7.6-3.7.2

Ссылки

Описание

** DISPUTED ** There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application.


Затронутые продукты
Container caasp/v4/389-ds:1.4.2:libsolv-tools-0.7.6-3.7.2
Container caasp/v4/389-ds:1.4.2:libzypp-17.15.0-3.9.1
Container caasp/v4/389-ds:1.4.2:zypper-1.14.30-3.7.2
Container caasp/v4/busybox:1.34.1:libsolv-tools-0.7.6-3.7.2

Ссылки
Уязвимость SUSE-RU-2019:2742-1