Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 555042 (CVE-2015-3908)

Summary: <app-admin/ansible-1.9.2: multiple vulnerabilities (CVE-2015-3908)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: jlec, pinkbyte
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugzilla.redhat.com/show_bug.cgi?id=1243468
Whiteboard: B3 [noglsa/cve]
Package list:
Runtime testing required: ---

Description Agostino Sarubbo gentoo-dev 2015-07-16 07:39:45 UTC
From ${URL} :

Ansible versions before 1.9.2 are vulnerable to a symlink attack that enables a malicious
zone/chroot/jail managed by ansible to escape into the managing host.

Upstream commits that fix this issue:

https://github.com/ansible/ansible/commit/548a7288a90c49e9b50ccf197da307eae525b899
https://github.com/ansible/ansible/commit/270be6a6f5852c5563976f060c80eff64decc89c
https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647
https://github.com/ansible/ansible/commit/0777d025051bf5cf3092aa79a9e6b67cec7064dd
https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b

CVE request: http://seclists.org/oss-sec/2015/q3/105

External References:

https://github.com/ansible/ansible


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Sergey Popov gentoo-dev 2015-07-16 17:17:41 UTC
Arches, please test and mark stable =app-admin/ansible-1.9.2

Target keywords: amd64 x86
Comment 2 Sergey Popov gentoo-dev 2015-07-16 18:11:00 UTC
amd64/x86 stable

GLSA vote: no
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2015-07-16 19:46:54 UTC
GLSA vote: no.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2015-07-20 13:12:09 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 5 Sergey Popov gentoo-dev 2015-07-23 08:27:18 UTC
Cleanup is done