openSUSE libzypp 16.21.2

CPE Details

openSUSE libzypp 16.21.2
16.21.2
2021-06-29
11h19 +00:00
2021-06-29
11h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:opensuse:libzypp:16.21.2:*:*:*:*:*:*:*

Informations

Vendor

opensuse

Product

libzypp

Version

16.21.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-18900 2020-01-24 15h15 +00:00 : Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.
4
Medium
CVE-2018-7685 2018-08-31 15h00 +00:00 The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.
7.8
High