CVE-2017-7435
published 2018-03-01CVE-2017-7435: In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious…
PriorityP339high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.84%
76.5th percentile
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libzypp | < libzypp 17.3.1-1 (bookworm) | libzypp 17.3.1-1 (bookworm) |
| opensuse | libzypp | <= 16.15.2 | — |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= unspecified < 20170803 | 20170803 |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gvfg-vcp7-gmf9: In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malici
ghsa_unreviewed·2022-05-13
CVE-2017-7435 [HIGH] CWE-20 GHSA-gvfg-vcp7-gmf9: In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malici
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
OSV
CVE-2017-7435: In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malici
osv·2018-03-01·CVSS 8.1
CVE-2017-7435 [HIGH] CVE-2017-7435: In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malici
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Debian
CVE-2017-7435: libzypp - In libzypp before 20170803 it was possible to add unsigned YUM repositories with...
vendor_debian·2017·CVSS 8.1
CVE-2017-7435 [HIGH] CVE-2017-7435: libzypp - In libzypp before 20170803 it was possible to add unsigned YUM repositories with...
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Scope: local
bookworm: resolved (fixed in 17.3.1-1)
bullseye: resolved (fixed in 17.3.1-1)
forky: resolved (fixed in 17.3.1-1)
sid: resolved (fixed in 17.3.1-1)
trixie: resolved (fixed in 17.3.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1009127https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.htmlhttps://www.suse.com/de-de/security/cve/CVE-2017-7435/https://bugzilla.suse.com/show_bug.cgi?id=1009127https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.htmlhttps://www.suse.com/de-de/security/cve/CVE-2017-7435/
2018-03-01
Published