CVE-2017-9269 PUBLISHED

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.

EPSS 0.45% · 63.5th percentile

Risk Scores

EPSS Score
0.45%
63.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibzypp0, 15.3.0-1build1

Timeline

References

Open in Interactive Console →