漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
libzypp accepts unsigned packages even when configured to check signatures
Vulnerability Description
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libzypp 输入验证漏洞
Vulnerability Description
libzypp(又名ZYPP)是美国Novell公司资助的一套开源的可管理引擎、驱动(例如:Linux应用程序YaST、Zypper)的工具。 libzypp 20170803之前版本中存在输入验证漏洞,该漏洞源于在检索未签名的包时,程序未向用户发出警告。攻击者可利用该漏洞向用户系统中注入恶意的RPM包。
CVSS Information
N/A
Vulnerability Type
N/A