A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

Project Subscriptions

Vendors Products
Libzypp Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 29 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse libzypp
Vendors & Products Suse
Suse libzypp

Mon, 29 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 29 Jun 2026 10:15:00 +0000

Type Values Removed Values Added
Description A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Title Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-06-29T11:44:36.827Z

Reserved: 2026-02-05T15:37:24.184Z

Link: CVE-2026-25707

cve-icon Vulnrichment

Updated: 2026-06-29T11:44:17.763Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T15:45:03Z

Weaknesses