libzypp(又名ZYPP)是美国Novell公司资助的一套开源的可管理引擎、驱动(例如:Linux应用程序YaST、Zypper)的工具。 libzypp 20170803之前的版本中存在安全漏洞。攻击者可通过添加未签名的YUM库利用该漏洞向用户系统中注入恶意的RPM包。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-14798 | local privilege escalation in SUSE postgresql init script | |
| CVE-2017-14804 | package builds could use directory traversal to write outside of target area | |
| CVE-2017-7436 | libzypp accepts unsigned packages even when configured to check signatures | |
| CVE-2017-9268 | open-build-service retrigger / wipebinaries hitting the wrong project bypassing access per | |
| CVE-2017-9269 | lack of keypinning in libzypp could lead to repository switching | |
| CVE-2017-9270 | post-auth arbitrary file write on cryptctl server | |
| CVE-2017-9271 | proxy credentials written to log files by zypper | |
| CVE-2017-9274 | osc executes spec code during "osc commit" | |
| CVE-2017-9286 | nextcloud package security issues with /srv/www/htdocs |
No comments yet