Release date:
Updated on:
Affected Systems:
Novell Libzypp <= 12.15.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63390
CVE (CAN) ID: CVE-2013-3704
Libzypp Properties is the software package management library.
Libzypp 12.15.0 and other versions have security vulnerabilities in rpm gpg key export and processing. If multiple key blobs are used, this function reports key fingerprints different from those of the signature library, this can trick users into believing that the fingerprint is issued by a trusted key. Attackers can bypass some security measures and perform unauthorized operations.
<* Source: vendor
Link: http://lists.opensuse.org/opensuse-updates/2013-09/msg00023.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.novell.com/products/linuxpackages/opensuse/libzypp.html
Refer:
Http://support.novell.com/security/cve/CVE-2013-3704.html
Https://bugzilla.novell.com/828672