libzypp accepts unsigned packages even when configured to check signatures
CVE-2017-7436
8.1HIGH
What is CVE-2017-7436?
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.
Affected Version(s)
libzypp < 20170803