Linux Security
    Linux Security
    Linux Security

    Debian LTS: DLA-2535-1: ansible security update

    Date 27 Jan 2021
    199
    Posted By LinuxSecurity Advisories
    CVE-2017-7481 Ansible fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject
    -------------------------------------------------------------------------
    Debian LTS Advisory DLA-2535-1                This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.debian.org/lts/security/                      Markus Koschany
    January 27, 2021                              https://wiki.debian.org/LTS
    -------------------------------------------------------------------------
    
    Package        : ansible
    Version        : 2.2.1.0-2+deb9u2
    CVE ID         : CVE-2017-7481 CVE-2019-10156 CVE-2019-14846 
                     CVE-2019-14904
    Debian Bug     : 862666 930065 942188
     
    Several security vulnerabilities were discovered in ansible, a configuration
    management, deployment, and task execution system.
    
    CVE-2017-7481
    
        Ansible fails to properly mark lookup-plugin results as unsafe. If an
        attacker could control the results of lookup() calls, they could inject
        Unicode strings to be parsed by the jinja2 templating system, resulting in
        code execution. By default, the jinja2 templating language is now marked as
        'unsafe' and is not evaluated.
    
    CVE-2019-10156
    
        A flaw was discovered in the way Ansible templating was implemented,
        causing the possibility of information disclosure through unexpected
        variable substitution. By taking advantage of unintended variable
        substitution the content of any variable may be disclosed.
    
    CVE-2019-14846
    
        Ansible was logging at the DEBUG level which lead to a disclosure of
        credentials if a plugin used a library that logged credentials at the DEBUG
        level. This flaw does not affect Ansible modules, as those are executed in
        a separate process.
    
    CVE-2019-14904
    
        A flaw was found in the solaris_zone module from the Ansible Community
        modules. When setting the name for the zone on the Solaris host, the zone
        name is checked by listing the process with the 'ps' bare command on the
        remote machine. An attacker could take advantage of this flaw by crafting
        the name of the zone and executing arbitrary commands in the remote host.
    
    For Debian 9 stretch, these problems have been fixed in version
    2.2.1.0-2+deb9u2.
    
    We recommend that you upgrade your ansible packages.
    
    For the detailed security status of ansible please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/ansible
    
    Further information about Debian LTS security advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://wiki.debian.org/LTS
    

    LinuxSecurity Poll

    Which is the best secure Linux distro for pentesting?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/50-which-is-the-best-secure-linux-distro-for-pentesting?task=poll.vote&format=json
    50
    radio
    [{"id":"174","title":"Kali Linux","votes":"9","type":"x","order":"1","pct":56.25,"resources":[]},{"id":"175","title":"Parrot OS","votes":"7","type":"x","order":"2","pct":43.75,"resources":[]},{"id":"176","title":"BlackArch Linux","votes":"0","type":"x","order":"3","pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350

    Please vote first in order to view vote results.


    VIEW MORE POLLS

    bottom 200

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.