{"id":"SUSE-SU-2021:0109-1","summary":"Security update for libzypp, zypper","details":"This update for libzypp, zypper fixes the following issues:\n\nUpdate zypper to version 1.14.41\n\nUpdate libzypp to 17.25.4\n\n- CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583)\n- RepoManager: Force refresh if repo url has changed (bsc#1174016)\n- RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966)\n- RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427).\n- RpmDb: If no database exists use the _dbpath configured in rpm.  Still makes sure a compat\n  symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910)\n- Fixed update of gpg keys with elongated expire date (bsc#179222)\n- needreboot: remove udev from the list (bsc#1179083)\n- Fix lsof monitoring (bsc#1179909)\n\nyast-installation was updated to 4.2.48:\n\n- Do not cleanup the libzypp cache when the system has low memory,\n  incomplete cache confuses libzypp later (bsc#1179415)\n\n","modified":"2026-03-11T07:17:09.447053Z","published":"2021-01-13T09:13:34Z","related":["CVE-2017-9271"],"upstream":["CVE-2017-9271"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20210109-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1050625"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174016"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177275"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177583"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178966"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179083"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179415"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179909"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9271"}],"affected":[{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Enterprise Installer Updates 15 SP2","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.25.5-3.25.6"}]}],"ecosystem_specific":{"binaries":[{"libzypp":"17.25.5-3.25.6","yast2-installation":"4.2.48-3.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0109-1.json"}},{"package":{"name":"yast2-installation","ecosystem":"SUSE:Linux Enterprise Installer Updates 15 SP2","purl":"pkg:rpm/suse/yast2-installation&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.48-3.16.1"}]}],"ecosystem_specific":{"binaries":[{"libzypp":"17.25.5-3.25.6","yast2-installation":"4.2.48-3.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0109-1.json"}},{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP2","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.25.5-3.25.6"}]}],"ecosystem_specific":{"binaries":[{"zypper-log":"1.14.41-3.14.10","zypper-needs-restarting":"1.14.41-3.14.10","zypper":"1.14.41-3.14.10","libzypp-devel":"17.25.5-3.25.6","libzypp":"17.25.5-3.25.6","yast2-installation":"4.2.48-3.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0109-1.json"}},{"package":{"name":"yast2-installation","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP2","purl":"pkg:rpm/suse/yast2-installation&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.48-3.16.1"}]}],"ecosystem_specific":{"binaries":[{"libzypp-devel":"17.25.5-3.25.6","libzypp":"17.25.5-3.25.6","yast2-installation":"4.2.48-3.16.1","zypper-log":"1.14.41-3.14.10","zypper-needs-restarting":"1.14.41-3.14.10","zypper":"1.14.41-3.14.10"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0109-1.json"}},{"package":{"name":"zypper","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP2","purl":"pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.41-3.14.10"}]}],"ecosystem_specific":{"binaries":[{"libzypp":"17.25.5-3.25.6","yast2-installation":"4.2.48-3.16.1","zypper-log":"1.14.41-3.14.10","zypper-needs-restarting":"1.14.41-3.14.10","zypper":"1.14.41-3.14.10","libzypp-devel":"17.25.5-3.25.6"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0109-1.json"}}],"schema_version":"1.7.5"}