Vulnerabilities
Vulnerable Software
Opensuse:  >> Zypper  Security Vulnerabilities
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
CVSS Score
4.0
EPSS Score
0.0
Published
2018-03-01
zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable.
CVSS Score
4.4
EPSS Score
0.001
Published
2013-12-02
zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a spoofed key.
CVSS Score
5.0
EPSS Score
0.003
Published
2008-07-21


Contact Us

Shodan ® - All rights reserved