PT-2006-7569 · Suse+1 · Suse Linux Enterprise+5
Published
1970-01-01
·
Updated
2018-10-30
·
CVE-2006-0803
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
openSUSE versions (affected versions not specified)
SUSE Linux Enterprise versions (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the liby2util and liby2util-devel packages of openSUSE and SUSE Linux Enterprise operating systems. These vulnerabilities can be exploited remotely and may lead to a breach of protected information integrity. The YaST Online Update script handling has a flaw in its signature verification functionality when using gpg 1.4.x, which prevents it from detecting malicious scripts or code that do not pass the signature check.
Recommendations
For openSUSE, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For SUSE Linux Enterprise, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Linux Enterprise
Yast
Gpg
Liby2Util
Liby2Util-Devel
Opensuse