File _patchinfo of Package patchinfo.3856
<patchinfo incident="3856"> <packager>mlandres</packager> <issue tracker="bnc" id="899510">Fix support using multiple base URLs for a repo</issue> <issue tracker="bnc" id="903405">VUL-1: CVE-2014-3566: libzypp: POODLE: libzypp should only talk TLS</issue> <issue tracker="fate" id="314603"></issue> <issue tracker="bnc" id="929483">zypper segfaults when installing specific package</issue> <issue tracker="bnc" id="929528">repo alias containing ] is not handled correctly</issue> <issue tracker="bnc" id="931601">libzypp SIGABRT in TargetImpl.commitFindFileConflicts.cc:141</issue> <issue tracker="bnc" id="932393">Zypper doesnt support client certificate authentication</issue> <issue tracker="bnc" id="725867">zypper: interpret repo:package as -f</issue> <issue tracker="bnc" id="820693">zypper.conf: confusing description for installRecommends</issue> <issue tracker="bnc" id="832519">zypper --sort-by-priority does not sort numerically</issue> <issue tracker="bnc" id="897301">bad formatting in zypper output</issue> <issue tracker="bnc" id="923800">typo in zypper manpage: mayching</issue> <issue tracker="bnc" id="925678">cronjob mails show shell color codes</issue> <issue tracker="bnc" id="925696">zypper segfaults when incorrect answer for solver is provided</issue> <issue tracker="bnc" id="929593">zypper lp --date off-by-one (day)</issue> <issue tracker="bnc" id="929990">YaST2 readds/reenables removed/disabled external Repos once the signature is accepted</issue> <issue tracker="bnc" id="933277">zypper info does not show support level</issue> <category>recommended</category> <rating>low</rating> <summary>Softwarestack update for openSUSE 13.2</summary> <description>This recommended update for the Softwarestack fixes the following issues: - zypper: + man: add section about GPG checks + repos/services: Show GPG Check status + Handle pkgGpgCheck callback (fate#314603) + download: fix wrong total (=0) counter in download message + download: actually abort on user request. + Clarify comment in zypper.conf (bnc#820693) + Fix format of sizes in output (bnc#897301) + Adapt enterprise product detection (bnc#933277) + removerepo: Warn user that deleting a service repo is a volatile change (bnc#929990) + Clarify 'zypper lp --date' description (bnc#929593) + Don't use color in XML mode. + fix table sort (bnc#832519) + only use ANSI codes on terminals (bnc#925678) + Fix prompt returning undefined default value after wrong input (bnc#925696) + man: fix typo (bnc#923800) + suppress MediaChangeReport while testing multiple baseurls (bnc#899510) + allow repo:package to reinstall from a different repo (bnc#725867) + fix wrong description of --force-resolution defaults + Updated translations - libzypp: + zypp.conf: Add config values for gpgcheck, repo_gpgcheck and pkg_gpgcheck. The default behavior 'gpgcheck=On' will automatically turn on the gpg signature check for packages downloaded from repository with unsigned metadata. If the repo metadata are signed, a faster comparison via checksums is done. By explicitly setting repo_gpgcheck or pkg_gpgcheck you can enforce the signature check of repository metadata or downloaded packages to be always performed. Those defaults can be overwritten per repository. (FATE#314603) + Downloader: Accept unsigned repository if pkgGpgCheck is ON. + Fix SSL client certificate authentication via URL option ssl_clientcert/ssl_clientkey (bnc#932393) + FindFileConflicts: avoid nested exception on user abort (bnc#931601) + Fix repo alias containing ']' not handled correctly (bnc#929528) + Fix SEGV when dumping rpm header with epoch (bnc#929483) + POODLE: libzypp should only talk TLS (bnc#903405) + Suppress MediaChangeReport while testing multiple baseurls (bnc#899510) - libsolv: + add forgotten sha-512 support to data_skip + speed up whatprovides lookup with a new helper array + fix dup with allowuninstall + improve alreadyinstalled handling of supplements + you really want to use rbconfig there</description> <zypp_restart_needed/> </patchinfo>