7.5
CVSSv2

CVE-2017-9269

Published: 01/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse libzypp -

Vendor Advisories

Debian Bug report logs - #899065 CVE-2017-9269 CVE-2017-7436 CVE-2017-7435 Package: src:libzypp; Maintainer for src:libzypp is Mike Gabriel <sunweaver@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 18 May 2018 19:33:02 UTC Severity: grave Tags: security Fixed in version libzypp/1731-1 Do ...