Описание
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
Ссылки
- ExploitThird Party Advisory
- Patch
Уязвимые конфигурации
EPSS
8.4 High
CVSS3
8.8 High
CVSS3
Дефекты
Связанные уязвимости
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
A relative path traversal in the "keyhint" option in repomd.xml parsin ...
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
Уязвимость механизма обработки файла метаданных репозитория repomd.xml библиотеки libzypp, позволяющая нарушителю выполнить произвольный код
EPSS
8.4 High
CVSS3
8.8 High
CVSS3