Description
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19401 | The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download. |
References
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-09-17T00:52:15.696Z
Reserved: 2018-03-05T00:00:00.000Z
Link: CVE-2018-7685
No data.
Status : Modified
Published: 2018-08-31T15:29:00.253
Modified: 2024-11-21T04:12:32.140
Link: CVE-2018-7685
No data.
OpenCVE Enrichment
No data.
EUVD