Описание
Security update for libsolv, libzypp, zypper
This update for libsolv, libzypp and zypper fixes the following issues:
libsolv was updated to version 0.6.36 fixes the following issues:
Security issues fixed:
- CVE-2018-20532: Fixed a NULL pointer dereference in testcase_read() (bsc#1120629).
- CVE-2018-20533: Fixed a NULL pointer dereference in testcase_str2dep_complex() (bsc#1120630).
- CVE-2018-20534: Fixed a NULL pointer dereference in pool_whatprovides() (bsc#1120631).
Non-security issues fixed:
- Made cleandeps jobs on patterns work (bsc#1137977).
- Fixed an issue multiversion packages that obsolete their own name (bsc#1127155).
- Keep consistent package name if there are multiple alternatives (bsc#1131823).
libzypp received following fixes:
- Fixes a bug where locking the kernel was not possible (bsc#1113296)
zypper received following fixes:
- Fixes a bug where the wrong exit code was set when refreshing repos if --root was used (bsc#1134226)
- Improved the displaying of locks (bsc#1112911)
- Fixes an issue where
httpsrepository urls caused an error prompt to appear twice (bsc#1110542) - zypper will now always warn when no repositories are defined (bsc#1109893)
Список пакетов
Container caasp/v4/nginx-ingress-controller:beta1
Container suse/ltss/sle12.5/sles12sp5:latest
Container suse/sles12sp3:latest
Container suse/sles12sp4:latest
Container suse/sles12sp5:latest
Image SLES12-SP5-Azure-BYOS
Image SLES12-SP5-Azure-Basic-On-Demand
Image SLES12-SP5-Azure-HPC-BYOS
Image SLES12-SP5-Azure-HPC-On-Demand
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-SAP-On-Demand
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-EC2-BYOS
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-EC2-SAP-On-Demand
Image SLES12-SP5-GCE-BYOS
Image SLES12-SP5-GCE-On-Demand
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-GCE-SAP-On-Demand
Image SLES12-SP5-OCI-BYOS-BYOS
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Enterprise Storage 5
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE OpenStack Cloud 8
Ссылки
- Link for SUSE-SU-2019:1972-1
- E-Mail link for SUSE-SU-2019:1972-1
- SUSE Security Ratings
- SUSE Bug 1109893
- SUSE Bug 1110542
- SUSE Bug 1111319
- SUSE Bug 1112911
- SUSE Bug 1113296
- SUSE Bug 1120629
- SUSE Bug 1120630
- SUSE Bug 1120631
- SUSE Bug 1127155
- SUSE Bug 1131823
- SUSE Bug 1134226
- SUSE Bug 1137977
- SUSE CVE CVE-2018-20532 page
- SUSE CVE CVE-2018-20533 page
- SUSE CVE CVE-2018-20534 page
Описание
There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2018-20532
- SUSE Bug 1120629
Описание
There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2018-20533
- SUSE Bug 1120630
Описание
There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-world application
Затронутые продукты
Ссылки
- CVE-2018-20534
- SUSE Bug 1120631