CVE-2017-7435
Summary
| CVE | CVE-2017-7435 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-01 20:29:00 UTC |
| Updated | 2023-11-07 02:50:00 UTC |
| Description | In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-7435 | SUSE | CONFIRM | www.suse.com | Vendor Advisory |
| Bug 1009127 – AUDIT-0: VUL-0: unsigned 3rd party repo accepted without warning | bugzilla.suse.com | ||
| [security-announce] SUSE-SU-2017:2040-1: important: Security update for | SUSE | lists.opensuse.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Ludwig Nussel of SUSE
There are currently no legacy QID mappings associated with this CVE.