8.1
CVSSv3

CVE-2017-7435

Published: 01/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

In libzypp prior to 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse libzypp

Vendor Advisories

Debian Bug report logs - #899065 CVE-2017-9269 CVE-2017-7436 CVE-2017-7435 Package: src:libzypp; Maintainer for src:libzypp is Mike Gabriel <sunweaver@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 18 May 2018 19:33:02 UTC Severity: grave Tags: security Fixed in version libzypp/1731-1 Do ...