ZeroHour

CVE-2017-9269

CVSS 3.0
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

Vendors
opensuse
Products
libzypp
Weakness
CWE-757, CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.