USN-3916-1: libsolv vulnerabilities
22 March 2019
Libzip could be made to crash if it received specially crafted input.
Releases
Packages
- libsolv - A dependency solver using a satisfiablility algorithm
Details
It was discovered that libsolv incorrectly handled certain malformed input. If a
user or automated system were tricked into opening a specially crafted file,
applications that rely on libsolv could be made to crash, resulting in a denial
of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.10
-
libsolv-tools
-
0.6.35-2ubuntu0.18.10.1
-
libsolv0
-
0.6.35-2ubuntu0.18.10.1
-
libsolvext0
-
0.6.35-2ubuntu0.18.10.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
References
Related notices
- USN-4851-1: libsolv-tools, libsolv, python-solv, libsolvext0-dev, libsolv0-dev, libsolv-perl, python3-solv, libsolv0, libsolv-doc, libsolvext0