Upstream information
CVE-2008-3187 at MITRE
Description
zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a spoofed key.
Novell/SUSE information
Novell Bugzilla entry:
398530
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| openSUSE 10.2 | libzypp >= 2.17.2-0.1 libzypp-devel >= 2.17.2-0.1 zypper >= 0.6.15-0.6
| |
| openSUSE 10.3 | libzypp >= 3.27.2-0.1 libzypp-devel >= 3.27.2-0.1 zypper >= 0.8.26-0.1
| |