Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

openSUSE 2019:0238-1 Moderate: ansible Security Advisory

opensuse
Calendar Grey February 23, 2019
Dist Opensuse Esm H88
A new release for openSUSE has been published, tackling moderate security issues in ansible, including risks of data leakage and flaws in input validation.
An update that fixes 6 vulnerabilities is now available.

Description

This update for ansible fixes the following issues:

Security vulnerabilities fixed:

- CVE-2018-16876: Respect no_log on retry and high verbosity (bsc#1118896)

- CVE-2018-16859: Windows - prevent sensitive content from appearing in

scriptblock logging (bsc#1116587)

- CVE-2018-10855: Fixed the honouration of the no_log option with failed

task iterations (boo#1097775)

- CVE-2017-7466: Fixed an input validation vulnerability in Ansible's

handling

of data sent from client systems

- CVE-2017-7481: Fixed a security issue with lookup return not tainting

the jinja2 environment (bsc#1038785)

Other bug fixes and changes:

- Update to version 2.7.6

* Added log message at -vvvv when using netconf connection listing

connection details.

* Changes how ansible-connection names socket lock files. They now use

the same name as the socket itself, and as such do not lock other

attempts on connections to the same host,...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2019-238=1

Package List

- openSUSE Backports SLE-15 (noarch):

ansible-2.7.6-bp150.3.3.1

References

https://www.suse.com/security/cve/CVE-2017-7466.html

https://www.suse.com/security/cve/CVE-2017-7481.html

https://www.suse.com/security/cve/CVE-2018-10855.html

https://www.suse.com/security/cve/CVE-2018-10875.html

https://www.suse.com/security/cve/CVE-2018-16859.html

https://www.suse.com/security/cve/CVE-2018-16876.html

https://bugzilla.suse.com/1056094

https://bugzilla.suse.com/1097775

--

Announcement ID: openSUSE-SU-2019:0238-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here