Novell Home

CVE-2008-3187

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-3187 at MITRE

Description

zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of service (package data corruption) via a spoofed key.

Novell/SUSE information

Novell Bugzilla entry: 398530

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.2
  • libzypp >= 2.17.2-0.1
  • libzypp-devel >= 2.17.2-0.1
  • zypper >= 0.6.15-0.6
openSUSE 10.3
  • libzypp >= 3.27.2-0.1
  • libzypp-devel >= 3.27.2-0.1
  • zypper >= 0.8.26-0.1

© 2012 Novell