rpm package
suse/libzypp&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-3200 | — | < 16.21.4-2.51.1 | 16.21.4-2.51.1 | May 18, 2021 | Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service | ||
| CVE-2019-18900 | — | < 16.21.2-2.45.1 | 16.21.2-2.45.1 | Jan 24, 2020 | : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3. | ||
| CVE-2019-20387 | — | < 16.21.4-2.51.1 | 16.21.4-2.51.1 | Jan 21, 2020 | repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema. | ||
| CVE-2017-9271 | — | < 16.22.13-65.3 | 16.22.13-65.3 | Mar 1, 2018 | The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. |
- CVE-2021-3200May 18, 2021affected < 16.21.4-2.51.1fixed 16.21.4-2.51.1
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
- CVE-2019-18900Jan 24, 2020affected < 16.21.2-2.45.1fixed 16.21.2-2.45.1
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.
- CVE-2019-20387Jan 21, 2020affected < 16.21.4-2.51.1fixed 16.21.4-2.51.1
repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
- CVE-2017-9271Mar 1, 2018affected < 16.22.13-65.3fixed 16.22.13-65.3
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.