CVE-2017-9269 on Ubuntu 16.04 LTS (xenial) - medium.
Description:
In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently downgrade to unsigned repositories with potential malicious content.