SUSE-SU-2017:3029-1
Dashboard / Vulnerabilities / SUSE-SU-2017:3029-1
SUSE-SU-2017:3029-1
Summary: Security update for ansible and monasca-installer
Details: This update for ansible provides version 2.2.3.0 and fixes the following security issues: - CVE-2017-7481: Data for lookup plugins used as variables was not being marked as 'unsafe' and could lead to unintentional disclosure of information. (bsc#1038785) - CVE-2016-9587: Prevent compromised host to execute commands on the controller (bsc#1019021). - CVE-2017-7466: Prevent arbitrary code execution on control nodes. For more information about the upstream bugs fixed, please see /usr/share/doc/packages/ansible/CHANGELOG.md Additionally, monasca-installer received several compatibility fixes for ansible.
References: https://www.suse.com/support/update/announcement/2017/suse-su-20173029-1/, https://bugzilla.suse.com/1019021, https://bugzilla.suse.com/1038785, https://bugzilla.suse.com/1056094, https://www.suse.com/security/cve/CVE-2016-9587, https://www.suse.com/security/cve/CVE-2017-7466, https://www.suse.com/security/cve/CVE-2017-7481
Affected packages
Package
Name: ansible
Purl: pkg:rpm/suse/ansible&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
