libzypp(又名ZYPP)是美国Novell公司资助的一套开源的可管理引擎、驱动(例如:Linux应用程序YaST、Zypper)的工具。 libzypp 2018年8月之前版本中存在输入验证漏洞。攻击者可利用该漏洞在不被检测到的情况下更改内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-14798 | local privilege escalation in SUSE postgresql init script | |
| CVE-2017-14804 | package builds could use directory traversal to write outside of target area | |
| CVE-2017-7435 | libzypp accepts unsigned 3rd party repo without warning | |
| CVE-2017-7436 | libzypp accepts unsigned packages even when configured to check signatures | |
| CVE-2017-9268 | open-build-service retrigger / wipebinaries hitting the wrong project bypassing access per | |
| CVE-2017-9270 | post-auth arbitrary file write on cryptctl server | |
| CVE-2017-9271 | proxy credentials written to log files by zypper | |
| CVE-2017-9274 | osc executes spec code during "osc commit" | |
| CVE-2017-9286 | nextcloud package security issues with /srv/www/htdocs |
No comments yet