4.3
CVSSv2

CVE-2013-3704

Published: 28/10/2013 Updated: 29/10/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The RPM GPG key import and handling feature in libzypp 12.15.0 and previous versions reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote malicious users to trick users into believing that the repository was signed by a more-trustworthy key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

novell libzypp

novell libzypp 12.3

novell libzypp 12.2

novell libzypp 12.1

novell libzypp 11.3

novell libzypp 11.4

novell libzypp 11.2