Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat: RHSA-2021:3872-01 Important: Ansible Engine 2 Security Fix

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Ansible security and bug fix update (2.9.27) Advisory ID: RHSA-2021:3872-01 Product: Red Hat Ansible Engine Advisory URL: https://access.redhat.com/errata/RHSA-2021:3872 Issue date: 2021-10-14 CVE Names: CVE-2021-3620 ==================================================================== 1. Summary: An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Engine 2 for RHEL 7 - noarch Red Hat Ansible Engine 2 for RHEL 8 - noarch 3. Description: Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. The following packages have been upgraded to a newer upstream version: ansible (2.9.27) Bug Fix(es): * CVE-2021-3620 Ansible: ansible-connection module discloses sensitive info in traceback error message See: https://github.com/ansible/ansible/blob/v2.9.27/changelogs/CHANGELOG-v2.9.rst for details on bug fixes in this release. 4. Solution: For details on how to apply this update, which includes the changes described in thisadvisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1975767 - CVE-2021-3620 Ansible: ansible-connection module discloses sensitive info in traceback error message 6. Package List: Red Hat Ansible Engine 2 for RHEL 7: Source: ansible-2.9.27-1.el7ae.src.rpm noarch: ansible-2.9.27-1.el7ae.noarch.rpm ansible-test-2.9.27-1.el7ae.noarch.rpm Red Hat Ansible Engine 2 for RHEL 8: Source: ansible-2.9.27-1.el8ae.src.rpm noarch: ansible-2.9.27-1.el8ae.noarch.rpm ansible-test-2.9.27-1.el8ae.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-3620 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYWiIHNzjgjWX9erEAQhS+Q/9Hh1WtMZpPNfeJZNXPkt80OmEqefnzTZ8 irH7m1o/Xu+1wIhtWEBvQJahZcMupZBivLCic/OMoJ7NfsnukGUwAPzncEXd9GF3 huZc2H5gp4Kt2Tsa6zHSkCpHNWdHuMkcqLWQKwW2PjKsvz+jDmM/SAyyoOmCqK2T tQiZdo76RwKJofLen6lPOauxMeQUtLIqwxfLIko4MINQCPTUHUxZ2RGweqQ7aHyF Xy6gtb/jfWuytqLopEb2VZyDLzo1bDzGDSgLWkgKc7EDozVTpXZjJP7R4UbNKa2M vF2kU296kg5k1hoqjCH/cJP6+DYTR1Ny6KGCiD17bPiMUzrRtKtXgja+utyN9T5m Ko9jZFmp3hkpzDXLDP05qiyOc1RjboUtnuu2HoVxyf9yqQPDCVJigFGrdK1wCdTP YO9XkfN2j/4kCQhkbg2idDooJO/POBOb3bIURX9QaESkmSQe8C2nKkwBiZBCjyMn 3Kz3VWWZEE5lIP+9NBbvD1bigFAwdwezDdqEm4VBhX6kYiO221UDe4ildp0PW/8/ qmEWI/FIVT+fXIiKELGM+047iwx2DJ2HXIBPIF1+DrhdS7zJYYfnoob2xhBTQRH7 eE2SVAa2n7+WtTIFg4i6uWhNNCo3/+sxn/sjQ2SK9hEUof4Svwha5Hyv5kGzdRDO JluGN+EE1Wc=5TrV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat releases an update for Ansible Engine version 2 addressing critical security vulnerabilities, notably CVE-2021-3621. Ensure your system isprotected!. Ansible Update, Red Hat Advisory, Security Impact, Announce Bug Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 14, 2021 Important Red Hat
98

RedHat: RHSA-2020-1544 Important Update for Ansible Engine 2.7

An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Ansible security and bug fix update (2.7.17) Advisory ID: RHSA-2020:1544-01 Product: Red Hat Ansible Engine Advisory URL: https://access.redhat.com/errata/RHSA-2020:1544 Issue date: 2020-04-22 CVE Names: CVE-2020-1733 CVE-2020-1735 CVE-2020-1737 CVE-2020-1739 CVE-2020-1740 CVE-2020-1746 CVE-2020-10684 CVE-2020-10685 ==================================================================== 1. Summary: An update for ansible is now available for Ansible Engine 2.7 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Ansible Engine 2.7 for RHEL 7 Server - noarch 3. Description: Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. The following packages have been upgraded to a newer upstream version: ansible (2.7.17) Bug Fix(es): * CVE-2020-10684 Ansible: code injection when using ansible_facts as a subkey * CVE-2020-10685 Ansible: modules which use files encrypted with vault are not properly cleanedup * CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive * CVE-2020-1735 ansible: path injection on dest parameter in fetch module * CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path * CVE-2020-1739 ansible: svn module leaks password when specified as a parameter * CVE-2020-1740 ansible: secrets readable after ansible-vault edit * CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules See: https://github.com/ansible/ansible/blob/v2.7.17/changelogs/CHANGELOG-v2.7.rst for details on bug fixes in this release. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1801735 - CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive 1802085 - CVE-2020-1735 ansible: path injection on dest parameter in fetch module 1802154 - CVE-2020-1737 ansible: Extract-Zip function in win_unzip module does not check extracted path 1802178 - CVE-2020-1739 ansible: svn module leaks password when specified as a parameter 1802193 - CVE-2020-1740 ansible: secrets readable after ansible-vault edit 1805491 - CVE-2020-1746 ansible: Information disclosure issue in ldap_attr and ldap_entry modules 1814627 - CVE-2020-10685 Ansible: modules which use files encrypted with vault are not properly cleaned up 1815519 - CVE-2020-10684 Ansible: code injection when using ansible_facts as a subkey 6. Package List: Red Hat Ansible Engine 2.7 for RHEL 7 Server: Source: ansible-2.7.17-1.el7ae.src.rpm noarch: ansible-2.7.17-1.el7ae.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2020-1733 https://access.redhat.com/security/cve/CVE-2020-1735 https://access.redhat.com/security/cve/CVE-2020-1737 https://access.redhat.com/security/cve/CVE-2020-1739 https://access.redhat.com/security/cve/CVE-2020-1740 https://access.redhat.com/security/cve/CVE-2020-1746 https://access.redhat.com/security/cve/CVE-2020-10684 https://access.redhat.com/security/cve/CVE-2020-10685 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXqBQhNzjgjWX9erEAQhvEg/+Ksod9qxxzrVN34cfFckIMXskkJitGlVt yRM3VRHtUQPO+Cu7rLPXIwZEo9XgNc8eCelD6KjcKz0AMvQShJZmka3WeJnwNqEg aBTh+UGQ8mFXrX87C8B89OLMlnXW643gMqMxIzT6PChdtB+5bGNAJQjBpagXa+Lb qX/9z2AXkuwS8J5B3foTtsimyHyPCzfnHJAjfrGmq8nL7VOoaeQGOB4RlGzSfxIT rULDV0s6QQD1UH6e6iiQhnncGr5Etf2Nt6OeHCQnIIL43M38VKmdu8W41vmqSYMZ m/rwtlXx7knf+sBblPjR+PvOX4esNCWUbNlieLOp1Q0bPfnCf5Qk++B0e6nxQ6LT m+7m8q8ps7/eZBjpBCZ4W4HzRIxrLJm/oDKYQwul7expcQ/IgbgbpvFaU9OiPWlq 7LgB1d/p52USlRbC34p3xqqpWTIl4wVjwgGdapoWr/wRa7tMvMxU803Bd6j/47xR FF48fM1VS0It0QUv2UTqKgviX6H6fEoCbg2AUKkb4QIGZN7Z7LPMGdk6FA//Uc/C Q29tnoiheXF0aTlwUeWKmRuIfMHXPiCRdjcOhaJRnWHHf23GzGuNeFrb4uGn8ibm rp7M82Sx5e+4CAjuoOhsYeiiNbg1gZpBazz8g5Bd+fC1pBxubbsWmJlShyoalwS9 /uJ0RbEisq8=h9wP -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical releases a significant enhancement for Ubuntu Server tackling various security vulnerabilities and resolving persistent bugs.. Ansible Engine Update,RHEL 7 Security,Important Ansible Advisory,Security Fixes Ansible. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 22, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here