You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke libsolv

Sigurnosni nedostaci programske biblioteke libsolv

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3916-1
March 22, 2019

libsolv vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10

Summary:

Libzip could be made to crash if it received specially crafted input.

Software Description:
– libsolv: A dependency solver using a satisfiablility algorithm

Details:

It was discovered that libsolv incorrectly handled certain malformed input. If a
user or automated system were tricked into opening a specially crafted file,
applications that rely on libsolv could be made to crash, resulting in a denial
of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
libsolv-tools 0.6.35-2ubuntu0.18.10.1
libsolv0 0.6.35-2ubuntu0.18.10.1
libsolvext0 0.6.35-2ubuntu0.18.10.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3916-1
CVE-2018-20532, CVE-2018-20533, CVE-2018-20534

Package Information:
https://launchpad.net/ubuntu/+source/libsolv/0.6.35-2ubuntu0.18.10.1

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEwZbe96kJeWh2OITRdyg1Qz0oXX0FAlyU7ewACgkQdyg1Qz0o
XX3C0w/8C3QBrHyKMx+dMGsjcgNz0KoP7rWqNDXh/1mMFV6BvaN/MeHebR1lHelh
fQoX/RjQAhhz44OHejc2Hsw2R+BQYj9LkUxhFEmmIgcOsd1pXTQjJVUhIA9ZFCqs
S59LYeI/L+tnzCo01B8U7EVVseM+1UPWgVjG1RYZuOlWaRfh17Vd4y4Nl/QPgbn1
jVRswY0lHaw8efaC6Ao2aXh21YTDHj+0Wia4/2yvswDcDIhqpnCw467qIaqVV85z
4jviJTxZQNVJ/yZWSOkIoETv9LwnXPEa4TcM7yrS1qMeW6n7aTNr6C6VtaJ6i89i
Ds3BdeRN1pf+KdfIvDQCBhsYEy5DU4asGpQXuk5cVqQWVZniST7MMSOPp+N+uQLk
+2P21c4ATSUFLly5FuyDAGsSe+D4F/PFR2P9lXmRgfXJ3GdBDIAaOchxHod09uCF
z3BX/VvC3EMhopBzTGTFGW8Ctlk4FyB/tUDgvHEyj7bEUnS4UucDi7fK90W1M4OB
sFjc1fyHNXNmOAGmYlDNgr1qZbqmDjC168itlIemqGIpvlXgmuyfB00EekoIG1AH
JyQyc+a6fVlQ+MxXV37UJXNHF1aTinEYz6EXY4Hfh/j48QI7WHDFz9I8H7FjKl3S
rqQGDr45fTPtmSIE1q+q489UHRxGgomb3JlYiqFTjPfcktag58w=
=RdWj
—–END PGP SIGNATURE—–

AutorFilip Karamatic
Cert idNCERT-REF-2019-03-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programske biblioteke libssh2

Otkriveni su sigurnosni nedostaci u programskoj bliboteci libssh2 za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog...

Close