Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2019-0114 Critical: Ansible Parameter Leakage And Path Traversal

mageia
Calendar Grey March 21, 2019
Dist Mageia Esm H88
Revised ansible software in Mageia resolves particular security flaws concerning data exposure and directory traversal.
The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837)

Summary

The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837).
The fetch module was susceptible to path traversal (CVE-2019-3828).

References

- https://bugs.mageia.org/show_bug.cgi?id=24395

- https://lists.debian.org/debian-security-announce/2019/msg00037.html

- https://www.cve.org/CVERecord?id=CVE-2019-3828

Resolution

SRPMS

- 6/core/ansible-2.4.6.0-1.3.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 21 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0114.html
Type: security
CVE: CVE-2019-3828

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here