In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libzypp | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade libzyppUpgrade yast2-pkg-bindingsUpgrade sles12sp2-docker-imageUpgrade zypperUpgrade yast2-pkg-bindings-devel-docUpgrade zypper-logUpgrade libzypp-develUpgrade libzypp-devel-doc | Aug 3, 2017 | Aug 3, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub