CVE-2017-7435: libzypp accepts unsigned 3rd party repo without warning
Published Mar 1, 2018
·Updated
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Affected Software
1 affected component
openSUSE Libzypp<=16.15.2
Event History
Mar 1, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2017-7435?
CVE-2017-7435 is a vulnerability in libzypp that allowed the addition of unsigned YUM repositories without warning, potentially allowing man-in-the-middle attacks or injection of malicious RPM packages.
2
How does CVE-2017-7435 affect Opensuse Libzypp?
CVE-2017-7435 affects Opensuse Libzypp versions up to and including 16.15.2.
3
What is the severity of CVE-2017-7435?
CVE-2017-7435 has a severity rating of 8.1 (Critical).
4
How can I fix CVE-2017-7435?
To fix CVE-2017-7435, update libzypp to a version after 20170803.
5
Where can I find more information about CVE-2017-7435?
More information about CVE-2017-7435 can be found at the following references: [1] [2] [3]