First published: Thu Mar 01 2018(Updated: )
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
Credit: meissner@suse.de
Affected Software | Affected Version | How to fix |
---|---|---|
Opensuse Zypper | ||
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-9271 is classified as medium.
To fix CVE-2017-9271, ensure that your zypper configuration does not log HTTP proxy credentials.
CVE-2017-9271 affects the zypper commandline package update tool on OpenSUSE and Fedora.
CVE-2017-9271 is categorized as a credential leakage vulnerability.
Local attackers can exploit CVE-2017-9271 to gain access to HTTP proxy credentials stored in the logfile.