CVE-2013-3704
28.10.2013, 22:55
The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might allow remote attackers to trick users into believing that the repository was signed by a more-trustworthy key.Enginsight
Vendor | Product | Version |
---|---|---|
novell | libzypp | 𝑥 ≤ 12.15.0 |
novell | libzypp | 11.2 |
novell | libzypp | 11.3 |
novell | libzypp | 11.4 |
novell | libzypp | 12.1 |
novell | libzypp | 12.2 |
novell | libzypp | 12.3 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration