Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat OpenStack 13.0 RHSA-2018:2585-01 Moderate: Ansible Update

An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: ansible security update Advisory ID: RHSA-2018:2585-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2018:2585 Issue date: 2018-08-29 CVE Names: CVE-2018-10855 CVE-2018-10874 CVE-2018-10875 ==================================================================== 1. Summary: An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - noarch 3. Description: Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. The following packages have been upgraded to a newer upstream version: ansible (2.4.5) Security Fix(es): * ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs (CVE-2018-10855) * ansible: Inventory variables are loaded from current working directory when running ad-hoc command that can lead to code execution (CVE-2018-10874) * ansible: ansible.cfg is being read from current working directory allowing possible code execution(CVE-2018-10875) For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Red Hat would like to thank Tobias Henkel (BMW Car IT GmbH), Brian Coca (Red Hat), and Michael Scherer (OSAS) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1588855 - CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs 1596528 - CVE-2018-10874 ansible: Inventory variables are loaded from current working directory when running ad-hoc command that can lead to code execution 1596533 - CVE-2018-10875 ansible: ansible.cfg is being read from current working directory allowing possible code execution 6. Package List: Red Hat OpenStack Platform 13.0: Source: ansible-2.4.6.0-1.el7ae.src.rpm noarch: ansible-2.4.6.0-1.el7ae.noarch.rpm Red Hat OpenStack Platform 13.0: Source: ansible-2.4.6.0-1.el7ae.src.rpm noarch: ansible-2.4.6.0-1.el7ae.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-10855 https://access.redhat.com/security/cve/CVE-2018-10874 https://access.redhat.com/security/cve/CVE-2018-10875 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBW4bEzNzjgjWX9erEAQjjKxAAia3g4kZ7b5TR6uYbQP71A0gEIr6xeQHj ylfZZcvl3sszuzhIQfsJejAawIxAG/IJ1Q2TisOEFzbokU3eOXOq6uBHAymiQdgP JpUHWnyGoJN8hN1dL/avDaNilVK5POY+XRwIhsGx2EqUhAFTTP9E/MwVSy1H81YE Kw+Dlxb3ikEIhcsbZsTI1POT0t69HVBkdtEPeSEgRdN5MI7zqjrm6FG4JSY1XghS 8WGlw60Nnu6E6bMO1aIEixNAdwZkfdkgydV6RVKYLXbc1mV1nDCnj0Z8ka5z+Hoe FiU1QpE1fzPvmJNBvKR45pdTMW1WC6sLaJyIqd5Rz6xt4KuIgNAoKd+/WmIJHdym WjniZVKYbXcXKLLXcn4/DGFNzA4lpWfNnwczu3xrNnF8ExkvgRSECcVuJc01vuNX unzsMMl+q4OkkJFFQn3GYGO+oQ/mna9rwo7Do9H5XBcfmwj4x9DgxNq3qEfzY1Yr EeL+CnzvSGwAX0qV2uW0Ot5jyJ100fSBIHk7B4bbbnEc/mdUEW+wabALnRJYsnkr qzQlV1QIXH6xyEZvcCboQnSrsjoeCcPf/Kq4GCoLygZi77S2XrsmRscCUovUaGS8 UfBq0XeJmN8lpJNRTV8q630wgkkUEh3LtbR+DSQugeNbnzjNerw4OY2mLN2qXxUq jPEI4g5p7MY=HcSS -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest security update for the Red Hat OpenStack Platform addresses vulnerabilities that may affect system integrity and stability, offering essential patches for identified flaws.. ansible update, Red Hat OpenStack, platform security, configuration management, moderate security. . LinuxSecurity.com Team

Calendar 2 Aug 29, 2018 Red Hat
98

Red Hat Enterprise Linux 7: RHSA-2017-2966-01 Moderate Ansible Security Fix

An update for ansible is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: ansible security, bug fix, and enhancement update Advisory ID: RHSA-2017:2966-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2017:2966 Issue date: 2017-10-19 CVE Names: CVE-2017-7550 ==================================================================== 1. Summary: An update for ansible is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - noarch 3. Description: Ansible is a simple model-driven configuration management, multi-node deployment, and remote-task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. The ansible packages have been upgraded to upstream version 2.4.0, which provides a number of bug fixes and enhancements over the previous version. For more information, please see the Ansible 2.4 Porting Guide linked in the References section. (BZ#1492477) Security Fix(es): * A flaw was found in the way Ansible passed certain parameters to the jenkins_plugin module. A remote attacker could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowingpasswords to be specified in the "params" argument, and noting this in the module documentation. (CVE-2017-7550) Red Hat would like to thank Stefano Mazzucco (Kirontech) for reporting this issue. Bug Fix(es): * A bug in the SELinux module, which caused a corruption of the SELinux configuration file, has been fixed. * Previously, some of the functionality of Ansible (the json_query filter) was unavailable, because the dependency on the python2-jmespath package was missing. Now, the missing dependency has been added. (BZ#1484910) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1473645 - CVE-2017-7550 ansible: jenkins_plugin module exposes passwords in remote host logs 1484910 - Require python-jmespath 6. Package List: Red Hat Enterprise Linux 7 Extras: Source: ansible-2.4.0.0-5.el7.src.rpm noarch: ansible-2.4.0.0-5.el7.noarch.rpm ansible-doc-2.4.0.0-5.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-7550 https://access.redhat.com/security/updates/classification/#moderate https://docs.ansible.com/projects/ansible/latest/porting_guides/porting_guide_2.4.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFZ6MKcXlSAg2UNWIIRApTfAJ4pFg9N8k3sPONpUTUAOKBCTwcQmwCgppfa qA0ZfHm6KzSUYyi7W8W02rQ=iTLq -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . New release for ansible provided for RHEL 7 Extras classified as Moderate; encompasses security patches and improvements.. ansible Update, Red Hat Security, Enterprise Linux 7, Security Fixes. . LinuxSecurity.com Team

Calendar 2 Oct 19, 2017 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here