Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44942

Опубликовано: 18 июн. 2026
Источник: debian
EPSS Низкий

Описание

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libzyppfixed17.38.13-1package
libzyppno-dsatrixiepackage
libzypppostponedbookwormpackage
libzypppostponedbullseyepackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=1267874

EPSS

Процентиль: 34%
0.00417
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
redhat
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
nvd
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

CVSS3: 6.5
github
около 2 месяцев назад

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

suse-cvrf
около 1 месяца назад

Security update for libzypp

EPSS

Процентиль: 34%
0.00417
Низкий