Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 37: 2023-89e8f3efc5 Critical: Salt Remote Execution Threat

fedora
Calendar Grey November 8, 2023
Dist Fedora Esm H88
Fedora 37 has rolled out an update for Salt, targeting the urgent CVE-2023-34049 vulnerability to enhance overall system security.
Fix for CVE-2023-34049

Summary

Salt is a distributed remote execution system used to execute commands and

query data. It was developed in order to bring the best solutions found in

the world of remote execution together and make them better, faster and more

malleable. Salt accomplishes this via its ability to handle larger loads of

information, and not just dozens, but hundreds or even thousands of individual

servers, handle them quickly and through a simple and manageable interface.

Update Information:

Fix for CVE-2023-34049

Change Log

* Mon Oct 30 2023 Gwyn Ciesla - 3005.4-1 - 3005.4

References


[ 1 ] Bug #2246812 - salt-3006.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2246812 [ 2 ] Bug #2246982 - CVE-2023-34049 salt: allows an attacker to force Salt-SSH to run their script [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2246982

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-89e8f3efc5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: salt
Product: Fedora 37
Version: 3005.4
Release: 1.fc37
Summary: A parallel remote execution system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here