Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 26: 2017-d5ef38bf2c Critical: Ansible Code Execution Risks

fedora
Calendar Grey April 17, 2017
Dist Fedora Esm H88
The latest Ansible release for Fedora 26 addresses earlier bug concerns and features a range of significant enhancements.
Many bugfixes and improvements

Summary

Ansible is a radically simple model-driven configuration management,

multi-node deployment, and remote task execution system. Ansible works

over SSH and does not require any software or daemons to be installed

on remote nodes. Extension modules can be written in any language and

are transferred to managed machines automatically.

Many bugfixes and improvements. See

https://github.com/ansible/ansible/blob/stable-2.3/CHANGELOG.md for full list of

changes. rst and html docs have been split out into a ansible-docs subpackage.

Includes fix for CVE-2017-7466

[ 1 ] Bug #1441355 - CVE-2017-7466 ansible: Arbitrary code execution on control node (incomplete fix for CVE-2016-9587) [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1441355

su -c 'dnf upgrade ansible' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 2.3.0.0
Release: 1.fc26
Summary: SSH-based configuration management, deployment, and task execution system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here