USN-3916-1: libsolv vulnerabilities

22 March 2019

Libzip could be made to crash if it received specially crafted input.

Releases

Packages

  • libsolv - A dependency solver using a satisfiablility algorithm

Details

It was discovered that libsolv incorrectly handled certain malformed input. If a
user or automated system were tricked into opening a specially crafted file,
applications that rely on libsolv could be made to crash, resulting in a denial
of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.10

After a standard system update you need to reboot your computer to make
all the necessary changes.