You are here
Home > Preporuke > Sigurnosni propusti programskog paketa salt

Sigurnosni propusti programskog paketa salt

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2016-105b3b8804
2016-01-15 20:06:26.124999
——————————————————————————–

Name : salt
Product : Fedora 23
Version : 2015.5.8
Release : 1.fc23
URL : http://saltstack.org/
Summary : A parallel remote execution system
Description :
Salt is a distributed remote execution system used to execute commands and
query data. It was developed in order to bring the best solutions found in
the world of remote execution together and make them better, faster and more
malleable. Salt accomplishes this via its ability to handle larger loads of
information, and not just dozens, but hundreds or even thousands of individual
servers, handle them quickly and through a simple and manageable interface.

——————————————————————————–
Update Information:

Update to bugfix release 2015.5.8
——————————————————————————–
References:

[ 1 ] Bug #1212784 – CVE-2015-1838 salt: insecure /tmp file handling in salt/modules/serverdensity_device.py
https://bugzilla.redhat.com/show_bug.cgi?id=1212784
[ 2 ] Bug #1212788 – CVE-2015-1839 salt: insecure /tmp file handling in salt/modules/chef.py
https://bugzilla.redhat.com/show_bug.cgi?id=1212788
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update salt’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2016-01-0005-ADV
CveCVE-2015-1838 CVE-2015-1839
ID izvornikaFEDORA-2016-105
Proizvodsalt
Izvorhttp://www.redhat.com
Top
More in Preporuke
Višestruke ranjivosti programskog paketa xen

Otkrivene su višestruke ranjivosti u programskom paketu xen za openSUSE. Zahvaćene su razne komponente, a ovisno o tipu ranjivosti, potencijalnim...

Close