CVE-2017-9269
published 2018-03-01CVE-2017-9269: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.29%
81.3th percentile
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libzypp | < libzypp 17.3.1-1 (bookworm) | libzypp 17.3.1-1 (bookworm) |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= 0 < 17.3.1-1 | 17.3.1-1 |
| suse | libzypp | >= unspecified < 201808 | 201808 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvp9-wx3h-666q: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downg
ghsa_unreviewed·2022-05-13
CVE-2017-9269 [CRITICAL] CWE-20 GHSA-fvp9-wx3h-666q: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downg
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
OSV
CVE-2017-9269: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downg
osv·2018-03-01·CVSS 9.8
CVE-2017-9269 [CRITICAL] CVE-2017-9269: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downg
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
Debian
CVE-2017-9269: libzypp - In libzypp before August 2018 GPG keys attached to YUM repositories were not cor...
vendor_debian·2017·CVSS 7.7
CVE-2017-9269 [HIGH] CVE-2017-9269: libzypp - In libzypp before August 2018 GPG keys attached to YUM repositories were not cor...
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
Scope: local
bookworm: resolved (fixed in 17.3.1-1)
bullseye: resolved (fixed in 17.3.1-1)
forky: resolved (fixed in 17.3.1-1)
sid: resolved (fixed in 17.3.1-1)
trixie: resolved (fixed in 17.3.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1045735https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.htmlhttps://www.suse.com/de-de/security/cve/CVE-2017-9269/https://bugzilla.suse.com/show_bug.cgi?id=1045735https://lists.opensuse.org/opensuse-security-announce/2017-08/msg00002.htmlhttps://www.suse.com/de-de/security/cve/CVE-2017-9269/
2018-03-01
Published