libzypp accepts unsigned packages even when configured to check signatures
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.8%
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
In short
libzypp was accepting unsigned software packages without warning users, allowing attackers to trick people into installing malicious software by intercepting downloads or compromising servers.
Technical detail
libzypp before 20170803 failed to enforce signature verification for RPM packages, allowing unsigned packages to be installed without user notification. The vulnerability enables man-in-the-middle attacks or compromised repositories to deliver malicious packages when signature checks were expected to be active.
Summary generated and translated by AI from the official description.
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SUSE · libzypp