libzypp before version 17.5.3 does not limit the size of download files allowing for a malicious mirror to serve files of infinite size and fill a client's storage space. Upstream Patch: https://github.com/openSUSE/libzypp/pull/128/files
Created libzypp tracking bugs for this issue: Affects: fedora-all [bug 1615233]
This was fixed a long time ago...