CVE-2017-7435

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:*

History

07 Nov 2023, 02:50

Type Values Removed Values Added
References (CONFIRM) https://bugzilla.suse.com/show_bug.cgi?id=1009127 - Issue Tracking, Third Party Advisory () https://bugzilla.suse.com/show_bug.cgi?id=1009127 -
References (CONFIRM) https://www.suse.com/de-de/security/cve/CVE-2017-7435/ - Vendor Advisory () https://www.suse.com/de-de/security/cve/CVE-2017-7435/ -
References (SUSE) https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html - Vendor Advisory () https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.html -

Information

Published : 2018-03-01 20:29

Updated : 2024-02-28 16:25


NVD link : CVE-2017-7435

Mitre link : CVE-2017-7435

CVE.ORG link : CVE-2017-7435


JSON object : View

Products Affected

opensuse

  • libzypp
CWE
CWE-20

Improper Input Validation