← Vulnerability feed

Vulnerability record · CVE-2018-7685 · published 31 August 2018

CVE-2018-7685: Opensuse libzypp improper verification of cryptographic signature vulnerability

Opensuse · Libzypp

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.

7.8 CVSS 3.0 High EPSS 0.29% · top 81.0% CWE-358 · CWE-358CWE-347 · Improper verification of cryptographic signature
7.8CVSS 3.0 base score, v2 4.6
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malicious warnings only displayed during download.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7685 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-9269Opensuse libzypp improper input validation vulnerabilityIn libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…EPSS 2.2%8.8CVE-2026-44941Opensuse libzypp relative path traversal vulnerabilityA relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a maliciou…EPSS 0.53%8.8CVE-2026-25707Opensuse libzypp relative path traversal vulnerabilityA relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repo…EPSS 0.60%8.1CVE-2017-7435Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…EPSS 1.8%8.1CVE-2017-7436Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…EPSS 1.8%3.3CVE-2019-18900Opensuse libzypp incorrect default permissions vulnerability: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 …EPSS 0.30%8.8CVE-2024-7965Google Chrome V8 inappropriate implementation allows heap corruptionGoogle Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2018-7685), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.