CVE-2017-7436

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/03/2018
Last modified:
07/11/2023

Description

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:* 16.15.2 (including)