LWN.net Logo

libzypp: key verification bypass

Package(s):libzypp CVE #(s):CVE-2013-3704
Created:September 12, 2013 Updated:September 18, 2013
Description:

From the openSUSE advisory:

libzypp was adjusted to enhance the RPM GPG key import/handling to avoid a problem with multiple key blobs. Attackers able to supplying a repository could let the packagemanager show another keys fingerprint while a second one was actually used to sign the repository (CVE-2013-3704).

Alerts:
openSUSE openSUSE-SU-2013:1432-1 2013-09-12
openSUSE openSUSE-SU-2013:1433-1 2013-09-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds