Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-25707

Опубликовано: 29 июн. 2026
Источник: debian
EPSS Низкий

Описание

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libzyppfixed17.38.11-1package
libzyppno-dsatrixiepackage
libzypppostponedbookwormpackage
libzypppostponedbullseyepackage

Примечания

  • https://github.com/openSUSE/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b (17.38.10)

EPSS

Процентиль: 35%
0.00421
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

CVSS3: 8.8
redhat
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

CVSS3: 8.8
nvd
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

CVSS3: 8.8
github
около 2 месяцев назад

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

suse-cvrf
около 2 месяцев назад

Security update for libzypp

EPSS

Процентиль: 35%
0.00421
Низкий