Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
libzypp .repo files can have an optional path which can lead to path traversal attacks
Vulnerability Description
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
路径遍历:’../filedir’
Vulnerability Title
SUSE libzypp 路径遍历漏洞
Vulnerability Description
SUSE libzypp是德国SUSE公司的一个软件包管理库。 SUSE libzypp存在路径遍历漏洞,该漏洞源于处理.repo文件中"path"组件时存在路径遍历,可能导致攻击者将内容写入zypp缓存之外的系统目录。以下版本受到影响:17.38.13版本之前的17.x版本和16.22.19版本之前的版本。
CVSS Information
N/A
Vulnerability Type
N/A