Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 520428 (CVE-2014-3563)

Summary: <app-admin/salt-2014.1.10: Insecure tmp-file creation in seed.py, salt-ssh, and salt-cloud (CVE-2014-3563)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: chutzpah
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: http://www.openwall.com/lists/oss-security/2014/08/21/9
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2014-08-21 17:48:22 UTC
From ${URL} :

We are pleased to announce the 2014.1.10 release of Salt. The release notes can be found here: 

http://docs.saltstack.com/en/latest/topics/releases/2014.1.10.html

The sources are available on pypi:

https://pypi.python.org/pypi/salt/2014.1.10

Salt 2014.1.10 fixes security issues documented by CVE-2014-3563: Insecure tmp-file creation in seed.py, salt-ssh, and salt-cloud. 
Upgrading is recommended.


@maintainer(s): since the fixed version is already in the tree, please remove the affected versions.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-08-25 15:48:59 UTC
CVE-2014-3563 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3563):
  Multiple unspecified vulnerabilities in Salt (aka SaltStack) before
  2014.1.10 allow local users to have an unspecified impact via vectors
  related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3)
  salt-cloud.
Comment 2 Patrick McLean gentoo-dev 2014-08-29 22:50:01 UTC
Old versions are now removed from the tree.
Comment 3 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-08-29 22:56:10 UTC
(In reply to Patrick McLean from comment #2)
> Old versions are now removed from the tree.

Much appreciated, thanks. 

No stabilized versions, closing noglsa.