The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.
2013-10-28T22:55:03.693
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | novell | libzypp | ≤ 12.15.0 | Yes |
Application | novell | libzypp | 11.2 | Yes |
Application | novell | libzypp | 11.3 | Yes |
Application | novell | libzypp | 11.4 | Yes |
Application | novell | libzypp | 12.1 | Yes |
Application | novell | libzypp | 12.2 | Yes |
Application | novell | libzypp | 12.3 | Yes |