Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7435

Опубликовано: 01 мар. 2018
Источник: nvd
CVSS3: 8.1
CVSS2: 9.3
EPSS Низкий

Описание

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:*
Версия до 16.15.2 (включая)

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

CVSS3: 8.1
debian
почти 8 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM reposit ...

CVSS3: 8.1
github
больше 3 лет назад

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.

suse-cvrf
больше 8 лет назад

Security update for libzypp

suse-cvrf
больше 8 лет назад

Security update for libzypp, zypper

EPSS

Процентиль: 66%
0.00521
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-20