Security Advisory

CVE-2017-7436

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-01 19:00:00
Last updated 2024-09-16 19:09:24
Assigner microfocus
CVSS score 8.1
State PUBLISHED

Description

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.