{"id":"SUSE-SU-2022:1128-1","summary":"Security update for libsolv, libzypp","details":"This update for libsolv, libzypp fixes the following issues:\n\nlibsolv to 0.6.39:\n\n- fix memory leaks in SWIG generated code\n- fix misparsing of '&' in attributes with libxml2\n- try to keep packages from a cycle close togther in the\n  transaction order (bsc#1189622)\n- fix split provides not working if the update includes a\n  forbidden vendor change (bsc#1195485)\n- fix segfault on conflict resolution when using bindings\n- do not replace noarch problem rules with arch dependent ones\n  in problem reporting\n- fix and simplify pool_vendor2mask implementation\n- bump version to 0.6.39\n\nlibzypp to 16.22.4:\n\n- Hint on ptf resolver conflicts (bsc#1194848)\n- Fix package signature check (bsc#1184501)\n  Pay attention that header and payload are secured by a valid\n  signature and report more detailed which signature is missing.\n- Set ZYPP_RPM_DEBUG=1 to capture verbose rpm command output.\n","modified":"2022-04-07T14:19:28Z","published":"2022-04-07T14:19:28Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20221128-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1189622"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195485"}],"affected":[{"package":{"name":"libsolv","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.39-2.27.32.2"}]}],"ecosystem_specific":{"binaries":[{"libsolv-tools":"0.6.39-2.27.32.2","libzypp-devel":"16.22.4-27.85.2","libzypp":"16.22.4-27.85.2","perl-solv":"0.6.39-2.27.32.2","python-solv":"0.6.39-2.27.32.2","libsolv-devel":"0.6.39-2.27.32.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1128-1.json"}},{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.22.4-27.85.2"}]}],"ecosystem_specific":{"binaries":[{"libsolv-devel":"0.6.39-2.27.32.2","libsolv-tools":"0.6.39-2.27.32.2","libzypp-devel":"16.22.4-27.85.2","libzypp":"16.22.4-27.85.2","perl-solv":"0.6.39-2.27.32.2","python-solv":"0.6.39-2.27.32.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1128-1.json"}}],"schema_version":"1.7.3"}