CVE-2017-9269

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/03/2018
Last modified:
07/11/2023

Description

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opensuse:libzypp:-:*:*:*:*:*:*:*