[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2019-3583 -- Oracle microdnf_createrepo_c_dnf_libcomps_libdnf_librepo_librhsm_libsolv_yum

ID: oval:org.secpod.oval:def:1504540Date: (C)2021-01-10   (M)2024-05-22
Class: PATCHFamily: unix




createrepo_c [0.11.0-3] - Backport patch to switch off timestamps on documentation in order to remove file conflicts [0.11.0-2] - Consistently produce valid URLs by prepending protocol. - modifyrepo_c: Prevent doubling of compression - Correct pkg count in headers if there were invalid pkgs - Add support for modular errata dnf [4.2.7-6] - Remove patch to not fail when installing modular RPMs without modular metadata [4.2.7-5] - Fix: --setopt and repo with dots [4.2.7-4] - Prevent printing empty Error Summary [4.2.7-3] - Update localizations from zanata - Accept multiple specs in repoquery options - Prevent switching modules in all cases - Change synchronization of rpm transaction to swdb - Print rpm error messages during transaction - Report missing default profile as an error - Describe a behavior when plugin is removed [4.2.7-2] - Add patch to not fail when installing modular RPMs without modular metadata [4.2.7-1] - Update to 4.2.7 - Fix package reinstalls during yum module remove - Fail when "-c" option is given nonexistent file - Reuse empty lock file instead of stopping dnf - Propagate comps "default" value correctly - Better search of provides in /bin/ - Add detection for armv7hcnl - Fix group install/upgrade when group is not available - Report not matching plugins when using --enableplugin/--disableplugin - Add support of modular FailSafe - Replace logrotate with build-in log rotation for dnf.log and dnf.rpm.log [4.2.6-1] - Update to 4.2.6 - Use improved config parser that preserves order of data - Follow RPM security policy for package verification - Update modules regardless of installed profiles - [conf] Use environment variables prefixed with DNF_VAR_ - Allow adjustment of repo from --repofrompath - Allow globs in setopt in repoid part - Add command abbreviations - Installroot now requires absolute path - librepo: Turn on debug logging only if debuglevel is greater than 2 - Document cachedir option - Enhance documentation - API examples - Enhance documentation of --whatdepends option - Update documentation: implemented plugins; options; deprecated commands - [doc] Add info of relation update_cache with fill_sack - Rename man page from dnf.automatic to dnf-automatic to match command name - Fix alias list command - Fix behavior of --bz option when specifying more values - Add protection of yum package - Fix list --showduplicates - Retain order of headers in search results - Solve traceback with the "dnf install @module" - Fix multilib obsoletes - Do not remove group package if other packages depend on it - Remove duplicates from "dnf list" and "dnf info" outputs - Fix the installation of completion_helper.py - Fix formatting of message about free space required - Fix installation failiure when duplicit RPMs are specified - Fix issues with terminal hangs when attempting bash completion - Allow plugins to terminate dnf - [provides] Enhanced detecting of file provides - [provides] Sort the output packages alphabetically [4.0.9.2-6] - Backport patch to unify --help with man for module-spec dnf-plugins-core [4.0.8-3] - Generate yum-utils instead of symlinking [4.0.8-2] - Update localizations from zanata - Rename dnf-utils to yum-utils - [builddep] Report all rpm errors - [config-manager] Behaviour of --setopt [4.0.8-1] - Update to 4.0.8 - [reposync] Enable timestamp preserving for downloaded data - [reposync] Download packages from all streams - Make yum-copr manpage available - [needs-restarting] Add --reboothint option - Set the cost of _dnf_local repo to 500, to make it preferred to normal repos [4.0.7-1] - Update to 4.0.7 - Use improved config parser that preserves order of data - Fix: copr disable command traceback - [doc] state repoid as repo identifier of config-manager - [leaves] Show multiply satisfied dependencies as leaves - [download] Fix downloading an rpm from a URL - [download] Do not download src without --source - [download] Fix problem with downloading src pkgs - [download] Fix download of src when not the latest requested libcomps [0.1.11-2] - Backport patch: Fix order of asserts in unit test [0.1.11-1] - Update to 0.1.11 libdnf [0.35.1-8.0.1] - Disable rhsm [Orabug: 29901202] - Replaced bugzilla.redhat.com with bugzilla.oracle.com in config [Orabug: 29656932] - Add support for apps that use libdnf to access yum url with "ociregion" variable [Orabug: 30121584] [0.35.1-8] - Enhanced fix of moving directories in minimal container [0.35.1-7] - Remove patch to not fail when installing modular RPMs without modular metadata [0.35.1-6] - Fix moving directories in minimal container [0.35.1-5] - Add suport for query sequence conversions [0.35.1-4] - Fix typo in error message - Update localizations from zanata - Dont disable nonexistent but required repositories - Ignore trailing blank lines of multiline value - Re-size includes map before re-computation [0.35.1-3] - Fix attaching and detaching of libsolvRepo and repo_internalize_trigger [0.35.1-2] - Add patch to not fail when installing modular RPMs without modular metadata [0.35.1-1] - Update to 0.35.1 - Skip invalid key files in "/etc/pki/rpm-gpg" with warning - Enable timestamp preserving for downloaded data - Fix "database is locked" error - Replace the "Failed to synchronize cache" message - Fix "no such table: main.trans_cmdline" error - Fix: skip_if_unavailable=true for local repositories - Add support of modular FailSafe - Add support of DNF main config file in context; used by PackageKit and microdnf - Exit gpg-agent after repokey import [0.33.0-1] - Update to 0.33.0 - Enhance sorting for module list - [DnfRepo] Add methods for alternative repository metadata type and download - Remove installed profile on module enable or disable - Enhance modular solver to handle enabled and default module streams differently - Add support of wild cards for modules - Exclude module pkgs that have conflict - Enhance config parser to preserve order of data, and keep comments and format - Improve ARM detection - Add support for SHA-384 - Return empty query if incorrect reldep - ConfigParser: Improve compatibility with Python ConfigParser and dnf-plugin-spacewalk - ConfigParser: Unify default set of string represenation of boolean values - Fix segfault when interrupting dnf process - Installroot now requires absolute path - Support "_none_" value for repo option "proxy" - Add support for Module advisories - Add support for xml:base attribute from primary.xml - Improve detection of Platform ID [0.22.5-6] - Rebuild for libsolv soname bump librepo [1.10.3-3] - Backport patch: Fix: Verification of checksum from file attr [1.10.3-2] - Backport patch: Define LRO_SUPPORTS_CACHEDIR only with zchunk [1.10.3-1] - Update to 1.10.3 - Exit gpg-agent after repokey import [1.10.1-1] - Update to 1.10.1 - Reduce download delays - Add an option to preserve timestamps of the downloaded files - Append the "?" part of repo URL after the path - Fix memory leaks librhsm [0.0.3-3] - Generate repofile for any architecture if "ALL" is specified libsolv [0.7.4-3] - Backport patches: Use OpenSSL for computing hashes [0.7.4-2] - Backport patch: Not considered excluded packages as a best candidate [0.7.4-1] - soname bump to "1" - incompatible API changes: * bindings: Selection.flags is now an attribute * repodata_lookup_num now works like the other lookup_num functions - new functions: * selection_make_matchsolvable * selection_make_matchsolvablelist * pool_whatmatchessolvable * repodata_search_arrayelement * repodata_lookup_kv_uninternalized * repodata_search_uninternalized * repodata_translate_dir - new repowriter interface to write solv files allowing better control over what gets written - support for filtered file lists with a custom filter - dropped support of REPOKEY_TYPE_U32 - selected bug fixes: * fix nasty off-by-one error in repo_write * do not autouninstall packages because of forcebest updates * fixed a couple of null pointer derefs and potential memory leaks * made disfavoring recommended packages work if strong recommends is enabled * no longer disable infarch rules when they dont conflict with the job * repo_add_rpmdb: do not copy bad solvables from the old solv file * fix cleandeps updates not updating all packages - new features: * support rpms new "^" version separator * support set/get_considered_list in bindings * new experimental SOLVER_FLAG_ONLY_NAMESPACE_RECOMMENDED flag * do favor evaluation before pruning allowing to favor specific package versions * bindings: support pool.matchsolvable, pool.whatmatchessolvable pool.best_solvables and selection.matchsolvable * experimental DISTTYPE_CONDA and REL_CONDA support microdnf [3.0.1-3] - Fix microdnf --help coredump [3.0.1-2] - Fix minor memory leaks - Use help2man to generate a man page

Platform:
Oracle Linux 8
Product:
microdnf
createrepo_c
dnf
libcomps
libdnf
librepo
librhsm
libsolv
yum
Reference:
ELSA-2019-3583
CVE-2018-20534
CVE-2019-3817
CVE    2
CVE-2019-3817
CVE-2018-20534
CPE    10
cpe:/a:rpm-software-management:microdnf
cpe:/a:rpm-software-management:libdnf
cpe:/a:baseurl:yum
cpe:/a:rpm-software-management:libcomps
...

© SecPod Technologies