USN-3916-1: libsolv vulnerabilities
libsolv vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.10
Summary
Libzip could be made to crash if it received specially crafted input.
Software Description
- libsolv – A dependency solver using a satisfiablility algorithm
Details
It was discovered that libsolv incorrectly handled certain malformed input. If a
user or automated system were tricked into opening a specially crafted file,
applications that rely on libsolv could be made to crash, resulting in a denial
of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
- Ubuntu 18.10
- libsolv-tools – 0.6.35-2ubuntu0.18.10.1
- libsolv0 – 0.6.35-2ubuntu0.18.10.1
- libsolvext0 – 0.6.35-2ubuntu0.18.10.1
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system update you need to reboot your computer to make
all the necessary changes.