The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828). . MGASA-2019-0114 - Updated ansible packages fix security vulnerability Publication date: 21 Mar 2019 URL: https://advisories.mageia.org/MGASA-2019-0114.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3828 The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828). References: - https://bugs.mageia.org/show_bug.cgi?id=24395 - https://lists.debian.org/debian-security-announce/2019/msg00037.html - https://www.cve.org/CVERecord?id=CVE-2019-3828 SRPMS: - 6/core/ansible-2.4.6.0-1.3.mga6 . Revised ansible software in Mageia resolves particular security flaws concerning data exposure and directory traversal.. ansible security, Mageia updates, parameter leakage, path traversal vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.