UBUNTU-CVE-2014-3563
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3563
UBUNTU-CVE-2014-3563
Summary:
Details: Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.
References: https://ubuntu.com/security/CVE-2014-3563, http://docs.saltstack.com/en/latest/topics/releases/2014.1.10.html, http://xforce.iss.net/xforce/xfdb/95392, http://seclists.org/oss-sec/2014/q3/428, https://github.com/saltstack/salt/commit/7d4c470f91fcb43f505bfd220605fede1041437c, https://github.com/saltstack/salt/commit/2b8953adcbf1527bb330b12c9d59f1753ecaf78d, https://www.cve.org/CVERecord?id=CVE-2014-3563, https://ubuntu.com/security/notices/USN-4769-1
Affected packages
Package
Name: salt
Purl: pkg:deb/ubuntu/[email protected]+ds-1ubuntu0.1~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
