In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
References
Configurations
History
No history.
Information
Published : 2018-03-01 20:29
Updated : 2023-11-07 02:50
NVD link : CVE-2017-7436
Mitre link : CVE-2017-7436
CVE.ORG link : CVE-2017-7436
JSON object : View
Products Affected
opensuse
- libzypp
CWE
CWE-20
Improper Input Validation