Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 520428 (CVE-2014-3563) - <app-admin/salt-2014.1.10: Insecure tmp-file creation in seed.py, salt-ssh, and salt-cloud (CVE-2014-3563)
Summary: <app-admin/salt-2014.1.10: Insecure tmp-file creation in seed.py, salt-ssh, a...
Status: RESOLVED FIXED
Alias: CVE-2014-3563
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-21 17:48 UTC by Agostino Sarubbo
Modified: 2014-08-29 22:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-08-21 17:48:22 UTC
From ${URL} :

We are pleased to announce the 2014.1.10 release of Salt. The release notes can be found here: 

http://docs.saltstack.com/en/latest/topics/releases/2014.1.10.html

The sources are available on pypi:

https://pypi.python.org/pypi/salt/2014.1.10

Salt 2014.1.10 fixes security issues documented by CVE-2014-3563: Insecure tmp-file creation in seed.py, salt-ssh, and salt-cloud. 
Upgrading is recommended.


@maintainer(s): since the fixed version is already in the tree, please remove the affected versions.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-08-25 15:48:59 UTC
CVE-2014-3563 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3563):
  Multiple unspecified vulnerabilities in Salt (aka SaltStack) before
  2014.1.10 allow local users to have an unspecified impact via vectors
  related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3)
  salt-cloud.
Comment 2 Patrick McLean gentoo-dev 2014-08-29 22:50:01 UTC
Old versions are now removed from the tree.
Comment 3 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-29 22:56:10 UTC
(In reply to Patrick McLean from comment #2)
> Old versions are now removed from the tree.

Much appreciated, thanks. 

No stabilized versions, closing noglsa.