rpm package
suse/libsolv&distro=SUSE Linux Enterprise Module for Development Tools 15
pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-18900 | — | < 0.7.10-3.22.1 | 0.7.10-3.22.1 | Jan 24, 2020 | : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3. | ||
| CVE-2018-20534 | — | < 0.7.5-3.12.2 | 0.7.5-3.12.2 | Dec 28, 2018 | There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real- | ||
| CVE-2018-20533 | — | < 0.7.5-3.12.2 | 0.7.5-3.12.2 | Dec 28, 2018 | There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service. | ||
| CVE-2018-20532 | — | < 0.7.5-3.12.2 | 0.7.5-3.12.2 | Dec 28, 2018 | There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service. | ||
| CVE-2018-7685 | — | < 0.6.35-3.5.2 | 0.6.35-3.5.2 | Aug 31, 2018 | The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during downlo | ||
| CVE-2017-9269 | — | < 0.6.35-3.5.2 | 0.6.35-3.5.2 | Mar 1, 2018 | In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content. |
- CVE-2019-18900Jan 24, 2020affected < 0.7.10-3.22.1fixed 0.7.10-3.22.1
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.
- CVE-2018-20534Dec 28, 2018affected < 0.7.5-3.12.2fixed 0.7.5-3.12.2
There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-
- CVE-2018-20533Dec 28, 2018affected < 0.7.5-3.12.2fixed 0.7.5-3.12.2
There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
- CVE-2018-20532Dec 28, 2018affected < 0.7.5-3.12.2fixed 0.7.5-3.12.2
There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.
- CVE-2018-7685Aug 31, 2018affected < 0.6.35-3.5.2fixed 0.6.35-3.5.2
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during downlo
- CVE-2017-9269Mar 1, 2018affected < 0.6.35-3.5.2fixed 0.6.35-3.5.2
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.