[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2019:2030-1 -- SLES zypper, libsolv-debuginfo, libsolv-debugsource, libsolv-devel, libsolv-tools, libyui-ncurses-pkg-debugsource, libyui-ncurses-pkg-devel, libyui-ncurses-pkg8, libyui-qt-pkg-debugsource, libyui-qt-pkg8, libzypp, python-solv, yast2-pkg-bindings, libyui-ncurses-pkg-doc, libyui-qt-pkg-doc, PackageKit, libpackagekit-glib2-18, libpackagekit-glib2-devel, libyui-qt-pkg-devel, typelib-1_0-PackageKitGlib-1_0

ID: oval:org.secpod.oval:def:89050765Date: (C)2023-10-16   (M)2024-05-16
Class: PATCHFamily: unix




This update for libzypp and libsolv fixes the following issues: Security issues fixed: - CVE-2018-20532: Fixed NULL pointer dereference at ext/testcase.c . - CVE-2018-20533: Fixed NULL pointer dereference at ext/testcase.c in libsolvext.a . - CVE-2018-20534: Fixed illegal address access at src/pool.h in libsolv.a . Fixed bugs and enhancements: - make cleandeps jobs on patterns work - Fixed an issue where libsolv failed to build against swig 4.0 by updating the version to 0.7.5 . - Virtualization host upgrade from SLES-15 to SLES-15-SP1 finished with wrong product name shown up . - Copy pattern categories from the rpm that defines the pattern . - Enhance scanning /sys for modaliases . - Prevent SEGV if the application sets an empty TextLocale . - Handle libgpgme error when gpg key is not completely read and user hits CTRL + C . - Added a hint when registration codes have expired . - Adds a better handling of an error when verifying any repository medium . - Will now only write type field when probing . - Fixes an issue where zypper has showed the info message "Installation aborted by user" while the installation was aborted by wicked . - Suppresses reporting `/memfd:` pseudo files . - Fixes an issue where zypper was not able to install or uninstall packages when rpm is unavailable . - Fixes an issue where locks were ignored . - Simplify complex locks so zypper can display them . - zypper will now set `SYSTEMD_OFFLINE=1` during chrooted commits . - no-recommends: Nevertheless consider resolver namespaces . - Removes world-readable bit from /var/log/zypp . - Does no longer fail service-refresh on a empty repoindex.xml . - Fixes soname due to libsolv ABI changes . - Add infrastructure to flag specific packages to trigger a reboot needed hint . This update for zypper 1.14.27 fixes the following issues: - bash-completion: add package completion for addlock - bash-completion: fix incorrect detection of command names - Offer to change the "runSearchPackages" config option at the prompt - Prompt: provide a "yes/no/always/never" prompt. - Prompt: support "#NUM" as answer to select the NUMth option... - Augeas: enable writing back changed option values - removelocale: fix segfault - Move needs-restarting command to subpackage - Allow empty string as argument - Provide a way to delete cache for volatile repositories - Adapt to boost-1.69 requiring explicit casts tribool-greater than bool - Show support status in info if not unknown - Fix installing plain rpm files with `zypper in` - Show only required info in the summary in quiet mode - Stay with legacy behavior and return ZYPPER_EXIT_INF_REBOOT_NEEDED only for patches. We don"t extend this return code to packages, although they may also carry the "reboot-needed" attribute. The preferred way to test whether the system needs to be rebooted is `zypper needs-rebooting`. - Skip repository on error - New commands for locale management: locales addlocale removelocale Inspect and manipulate the systems `requested locales`, aka. the languages software packages should try support by installing translations, dictionaries and tools, as far as they are available. - Don"t throw, just warn if options are repeated - Fix detection whether stdout is a tty - Fix broken --plus-content switch - Fix broken --replacefiles switch - Extend zypper source-install - Fix inconsistent results for search - Show reboot hint in zypper ps and summary - Improve handling of partially locked packages - Fix wrong default values in help text - Fixed broken argument parsing for --reposd-dir - Fix wrong zypp::indeterminate use - CLI parser: fix broken initialization enforcing "select by name" - zypper.conf: [commit] autoAgreeWithLicenses {=false} - locks: Fix printing of versioned locks - locks: create and write versioned locks correctly - patch: --with update may implicitly assume --with-optional - no-recommends: Nevertheless consider resolver namespaces - Optionally run "zypper search-packages" after "search" - zypper.conf: Add [search]runSearchPackages config variable. - Don"t iterate twice on --no-cd - zypper-log: Make it Python 3 compatible - man: mention /etc/zypp/needreboot config file - Add `needs-restarting` shell script and manpage - Add zypper needs-rebooting command - Introduce new zypper command framefork. Migrated commands so far: addlock addrepo addservice clean cleanlocks modifyrepo modifyservice ps refresh refresh-services removelock removerepo removeservice renamerepo repos services - MediaChangeReport: fix https URLs causing 2 prompts on error

Platform:
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Product:
zypper
libsolv-debuginfo
libsolv-debugsource
libsolv-devel
libsolv-tools
libyui-ncurses-pkg-debugsource
libyui-ncurses-pkg-devel
libyui-ncurses-pkg8
libyui-qt-pkg-debugsource
libyui-qt-pkg8
libzypp
python-solv
yast2-pkg-bindings
libyui-ncurses-pkg-doc
libyui-qt-pkg-doc
PackageKit
libpackagekit-glib2-18
libpackagekit-glib2-devel
libyui-qt-pkg-devel
typelib-1_0-PackageKitGlib-1_0
Reference:
SUSE-SU-2019:2030-1
CVE-2018-20532
CVE-2018-20533
CVE-2018-20534
CVE    3
CVE-2018-20532
CVE-2018-20534
CVE-2018-20533
CPE    17
cpe:/a:libyui:libyui-ncurses-pkg-devel
cpe:/a:opensuse:libzypp
cpe:/a:libsolv:libsolv-devel
cpe:/a:libyui:libyui-ncurses-pkg-debugsource
...

© SecPod Technologies