File _patchinfo of Package patchinfo.1926
<patchinfo incident="1926"> <packager>mlandres</packager> <issue tracker="bnc" id="828672"></issue> <issue tracker="cve" id="CVE-2013-3704"></issue> <category>security</category> <rating>moderate</rating> <summary>libzypp: security fixes in RPM GPG key import parsing</summary> <description> libzypp was adjusted to enhance the RPM GPG key import/handling to avoid a problem with multiple key blobs. Attackers able to supplying a repository could let the packagemanager show another keys fingerprint while a second one was actually used to sign the repository (CVE-2013-3704). </description> <zypp_restart_needed/> </patchinfo>