VYPR

rpm package

suse/libzypp&distro=SUSE Linux Enterprise Server 12 SP3-BCL

pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL

Vulnerabilities (6)

  • CVE-2021-3200May 18, 2021
    affected < 16.21.4-2.51.1fixed 16.21.4-2.51.1

    Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service

  • CVE-2019-18900Jan 24, 2020
    affected < 16.21.2-2.45.1fixed 16.21.2-2.45.1

    : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.

  • CVE-2019-20387Jan 21, 2020
    affected < 16.21.4-2.51.1fixed 16.21.4-2.51.1

    repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.

  • CVE-2018-20534Dec 28, 2018
    affected < 16.20.2-27.60.4fixed 16.20.2-27.60.4

    There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that the issue affects the test suite and not the underlying library. It cannot be exploited in any real-

  • CVE-2018-20533Dec 28, 2018
    affected < 16.20.2-27.60.4fixed 16.20.2-27.60.4

    There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.

  • CVE-2018-20532Dec 28, 2018
    affected < 16.20.2-27.60.4fixed 16.20.2-27.60.4

    There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.