cbcvebase.
CVE-2017-9269
published 2018-03-01

CVE-2017-9269: In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to…

PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.29%
81.3th percentile
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlibzypp< libzypp 17.3.1-1 (bookworm)libzypp 17.3.1-1 (bookworm)
suselibzypp>= 0 < 17.3.1-117.3.1-1
suselibzypp>= 0 < 17.3.1-117.3.1-1
suselibzypp>= 0 < 17.3.1-117.3.1-1
suselibzypp>= 0 < 17.3.1-117.3.1-1
suselibzypp>= unspecified < 201808201808

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.