In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libzypp | Jul 30, 2024 | Mar 1, 2018 |
| Suse | — | Upgrade zypper-aptitudeUpgrade zypper-needs-restartingUpgrade zypper-logUpgrade zypperUpgrade yast2-pkg-bindingsUpgrade yast2-pkg-bindings-devel-docUpgrade sles12sp2-docker-imageUpgrade libzypp-develUpgrade libzyppUpgrade libzypp-devel-doc | Aug 3, 2017 | Aug 3, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub