The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.
References
Configurations
History
No history.
Information
Published : 2018-08-31 15:29
Updated : 2023-11-07 03:01
NVD link : CVE-2018-7685
Mitre link : CVE-2018-7685
CVE.ORG link : CVE-2018-7685
JSON object : View
Products Affected
opensuse
- libzypp