Novell Libzypp Unsigned Packages And Repositories Handling Unspecified Security Bypass Vulnerability
BID:100501
Info
Novell Libzypp Unsigned Packages And Repositories Handling Unspecified Security Bypass Vulnerability
| Bugtraq ID: | 100501 |
| Class: | Design Error |
| CVE: |
CVE-2017-7435 CVE-2017-7436 CVE-2017-9269 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2017 12:00AM |
| Updated: | Aug 03 2017 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SuSE Linux Enterprise Software Development Kit 12-SP3 SuSE Linux Enterprise Software Development Kit 12 SP2 SuSE Linux Enterprise Server for Raspberry Pi 12-SP2 SuSE Linux Enterprise Server 12-SP2 SuSE Linux Enterprise Server 12 SP3 SuSE Linux Enterprise Server 12 GA SuSE Linux Enterprise Desktop 12-SP2 SuSE Linux Enterprise Desktop 12 SP3 openSUSE Leap 42.2 OpenStack Cloud Magnum Orchestration 7 Novell Libzypp 16.15.1 Novell Libzypp 16.15 Novell Libzypp 12.3 Novell Libzypp 12.15.0 Novell Libzypp 11.4 Novell Libzypp 11.3 Novell Libzypp 11.2 |
| Not Vulnerable: |
Novell Libzypp 16.15.5 Novell Libzypp 16.15.4 Novell Libzypp 16.15.3 Novell Libzypp 16.15.2 |
Exploit / POC
Novell Libzypp Unsigned Packages And Repositories Handling Unspecified Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Novell Libzypp Unsigned Packages And Repositories Handling Unspecified Security Bypass Vulnerability
References:
References:
- CVE-2017-7435, CVE-2017-7436 and CVE-2017-9269: libzypp-16.15.2 and higher will (Micro Focus)
- Libzypp Home Page (Novell)