Inclusion of Sensitive Information in Log Files in zypper - CVE-2017-9271

 

Inclusion of Sensitive Information in Log Files in zypper - CVE-2017-9271

Published: January 15, 2025


Vulnerability identifier: #VU102829
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9271
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to commandline package update tool zypper writes HTTP proxy credentials into its logfile. A local user can read the log files and gain access to sensitive data.


Affected software

zypper
libsolv-devel-debuginfo
python3-solv-debuginfo
ruby-solv
ruby-solv-debuginfo
python3-solv
perl-solv-debuginfo
perl-solv
libsolv-tools-debuginfo
libsolv-tools
libsolv-debuginfo
libsolv-debugsource
libsolv-devel
python-solv-debuginfo
python-solv
zypper-log
zypper-debugsource
zypper-debuginfo
zypper-needs-restarting
libsigc-2_0-0-debuginfo
libsigc-2_0-0
libsigc++2-debugsource
libsigc++2-devel
libyui-qt-pkg-debugsource
libyui-qt-pkg-devel
libyui-qt-pkg9
libyui-qt-pkg9-debuginfo
libyui-qt-pkg-doc
libyui-ncurses-pkg-debugsource
libyui-ncurses-pkg-devel
libyui-ncurses-pkg9
libyui-ncurses-pkg9-debuginfo
libyui-ncurses-pkg-doc
yast2-installation
yast2-pkg-bindings
yast2-pkg-bindings-debuginfo
yast2-pkg-bindings-debugsource
libzypp-debuginfo
libzypp-debugsource
libzypp-devel-doc
libzypp
libzypp-devel
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Retail Branch Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Installer
Fedora
Dell Secure Connect Gateway

How to mitigate CVE-2017-9271

Install updates from vendor's website.

zypper - addressed in versions 1.13.66-21.61.3, 1.14.43-3.34.1, 1.14.43-3.49.1
libsolv-devel-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
python3-solv-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
ruby-solv - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
ruby-solv-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
python3-solv - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
perl-solv-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
perl-solv - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
libsolv-tools-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
libsolv-tools - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
libsolv-debuginfo - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
libsolv-debugsource - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
libsolv-devel - addressed in versions 0.7.17-3.32.1, 0.7.17-3.40.1
python-solv-debuginfo - update to 0.7.17-3.40.1
python-solv - update to 0.7.17-3.40.1
zypper-log - addressed in versions 1.13.66-21.61.3, 1.14.43-3.34.1, 1.14.43-3.49.1
zypper-debugsource - addressed in versions 1.13.66-21.61.3, 1.14.43-3.34.1, 1.14.43-3.49.1
zypper-debuginfo - addressed in versions 1.13.66-21.61.3, 1.14.43-3.34.1, 1.14.43-3.49.1
zypper - update to 1.14.42-1.fc33
zypper-needs-restarting - update to 1.14.43-3.34.1
libsigc-2_0-0-debuginfo - update to 2.10.0-3.7.1
libsigc-2_0-0 - update to 2.10.0-3.7.1
libsigc++2-debugsource - update to 2.10.0-3.7.1
libsigc++2-devel - update to 2.10.0-3.7.1
libyui-qt-pkg-debugsource - update to 2.45.28-3.10.1
libyui-qt-pkg-devel - update to 2.45.28-3.10.1
libyui-qt-pkg9 - update to 2.45.28-3.10.1
libyui-qt-pkg9-debuginfo - update to 2.45.28-3.10.1
libyui-qt-pkg-doc - update to 2.45.28-3.10.1
libyui-ncurses-pkg-debugsource - update to 2.48.9-7.7.1
libyui-ncurses-pkg-devel - update to 2.48.9-7.7.1
libyui-ncurses-pkg9 - update to 2.48.9-7.7.1
libyui-ncurses-pkg9-debuginfo - update to 2.48.9-7.7.1
libyui-ncurses-pkg-doc - update to 2.48.9-7.7.1
yast2-installation - update to 4.0.77-3.22.5
yast2-pkg-bindings - update to 4.1.3-3.10.3
yast2-pkg-bindings-debuginfo - update to 4.1.3-3.10.3
yast2-pkg-bindings-debugsource - update to 4.1.3-3.10.3
Dell Secure Connect Gateway - update to 5.26.00.18
libzypp-debuginfo - addressed in versions 16.22.13-65.3, 17.25.8-3.48.1, 17.25.8-3.66.1
libzypp-debugsource - addressed in versions 16.22.13-65.3, 17.25.8-3.48.1, 17.25.8-3.66.1
libzypp-devel-doc - update to 16.22.13-65.3
libzypp - addressed in versions 16.22.13-65.3, 17.25.8-3.48.1, 17.25.8-3.66.1
libzypp-devel - addressed in versions 16.22.13-65.3, 17.25.8-3.48.1, 17.25.8-3.66.1
libzypp - update to 17.25.6-1.fc33

External References

Related Security Bulletins