Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 555042 (CVE-2015-3908) - <app-admin/ansible-1.9.2: multiple vulnerabilities (CVE-2015-3908)
Summary: <app-admin/ansible-1.9.2: multiple vulnerabilities (CVE-2015-3908)
Status: RESOLVED FIXED
Alias: CVE-2015-3908
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa/cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2015-07-16 07:39 UTC by Agostino Sarubbo
Modified: 2015-07-23 08:27 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2015-07-16 07:39:45 UTC
From ${URL} :

Ansible versions before 1.9.2 are vulnerable to a symlink attack that enables a malicious
zone/chroot/jail managed by ansible to escape into the managing host.

Upstream commits that fix this issue:

https://github.com/ansible/ansible/commit/548a7288a90c49e9b50ccf197da307eae525b899
https://github.com/ansible/ansible/commit/270be6a6f5852c5563976f060c80eff64decc89c
https://github.com/ansible/ansible/commit/952166f48eb0f5797b75b160fd156bbe1e8fc647
https://github.com/ansible/ansible/commit/0777d025051bf5cf3092aa79a9e6b67cec7064dd
https://github.com/ansible/ansible/commit/ca2f2c4ebd7b5e097eab0a710f79c1f63badf95b

CVE request: http://seclists.org/oss-sec/2015/q3/105

External References:

https://github.com/ansible/ansible


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Sergey Popov gentoo-dev 2015-07-16 17:17:41 UTC
Arches, please test and mark stable =app-admin/ansible-1.9.2

Target keywords: amd64 x86
Comment 2 Sergey Popov gentoo-dev 2015-07-16 18:11:00 UTC
amd64/x86 stable

GLSA vote: no
Comment 3 Mikle Kolyada archtester Gentoo Infrastructure gentoo-dev Security 2015-07-16 19:46:54 UTC
GLSA vote: no.
Comment 4 Yury German Gentoo Infrastructure gentoo-dev 2015-07-20 13:12:09 UTC
Maintainer(s), please drop the vulnerable version(s).
Comment 5 Sergey Popov gentoo-dev 2015-07-23 08:27:18 UTC
Cleanup is done