In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: microfocus

Published: 2017-08-03T00:00:00

Updated: 2021-01-06T16:15:46

Reserved: 2017-05-29T00:00:00


Link: CVE-2017-9269

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-03-01T20:29:00.820

Modified: 2023-11-07T02:50:38.683


Link: CVE-2017-9269

JSON object: View

cve-icon Redhat Information

No data.