File _patchinfo of Package patchinfo.33123
<patchinfo incident="33123"> <issue tracker="cve" id="2024-0217"/> <issue tracker="bnc" id="1218544">VUL-0: CVE-2024-0217: PackageKit: use-after-free in Idle function callback</issue> <issue tracker="bnc" id="1221525">AutoYaST not upgrading all packages for SLES12 to SLES15 offline upgrade</issue> <issue tracker="bnc" id="1218171">zypper "lr" URI doesnt always match what zypper "ref" or "dup" will use</issue> <issue tracker="bnc" id="1175678">complete packages --unneeded featureset (mostly "apt-mark auto")</issue> <issue tracker="jsc" id="OBS-301"/> <issue tracker="jsc" id="PED-8014"/> <packager>mlandres</packager> <rating>moderate</rating> <category>recommended</category> <summary>Recommended update for libzypp, zypper, PackageKit</summary> <description>This update for libzypp, zypper, PackageKit fixes the following issues: - Fixup New VendorSupportOption flag VendorSupportSuperseded (jsc#OBS-301, jsc#PED-8014) - CVE-2024-0217: Check that Finished signal is emitted at most once (bsc#1218544) - Add resolver option 'removeOrphaned' for distupgrade (bsc#1221525) - New VendorSupportOption flag VendorSupportSuperseded (jsc#OBS-301, jsc#PED-8014) - Add default stripe minimum - Don't expose std::optional where YAST/PK explicitly use c++11. - Digest: Avoid using the deprecated OPENSSL_config - version 17.32.0 - ProblemSolution::skipsPatchesOnly overload to handout the patches - Show active dry-run/download-only at the commit propmpt - Add --skip-not-applicable-patches option - Fix printing detailed solver problem description - Fix bash-completion to work with right adjusted numbers in the 1st column too - Set libzypp shutdown request signal on Ctrl+C - In the detailed view show all baseurls not just the first one (bsc#1218171) </description> <zypp_restart_needed/> </patchinfo>




