File _patchinfo of Package patchinfo.25760

<patchinfo incident="25760">
  <issue tracker="bnc" id="1202616">GPL 2.0 / 3.0 license conflict in multipath-tools</issue>
  <issue tracker="bnc" id="1187534">some zfcp devices have large/negative LUN IDs</issue>
  <issue tracker="bnc" id="1202739">VUL-0: CVE-2022-41973 CVE-2022-41974: multipath-tools: multipathd: authorization bypass and symlink attack</issue>
  <issue tracker="cve" id="2022-41973"/>
  <issue tracker="cve" id="2022-41974"/>
  <packager>mwilck</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for multipath-tools</summary>
  <description>This update for multipath-tools fixes the following issues:

- CVE-2022-41973: Fixed a symlink attack in multipathd. (bsc#1202739)
- CVE-2022-41974: Fixed an authorization bypass issue in multipathd. (bsc#1202739)
- Avoid linking to libreadline to avoid licensing issue (bsc#1202616)
- Fix that some zfcp devices have large/negative LUN IDs (bsc#1187534)
</description>
</patchinfo>
openSUSE Build Service is sponsored by