[Git][security-tracker-team/security-tracker][master] 2 commits: Readd ansible to dla-needed.txt
Markus Koschany
apo at debian.org
Wed Jan 27 17:00:53 GMT 2021
Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3d9b13e3 by Markus Koschany at 2021-01-27T17:57:52+01:00
Readd ansible to dla-needed.txt
There are more unresolved issues.
- - - - -
e183188e by Markus Koschany at 2021-01-27T18:00:15+01:00
Remove no-dsa tags for upcoming ansible update.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -106606,7 +106606,6 @@ CVE-2019-14905 (A vulnerability was found in Ansible Engine versions 2.9.x befor
CVE-2019-14904 (A flaw was found in the solaris_zone module from the Ansible Community ...)
- ansible 2.9.4+dfsg-1 (low)
[buster] - ansible <no-dsa> (Minor issue)
- [stretch] - ansible <no-dsa> (Minor issue)
[jessie] - ansible <not-affected> (Vulnerable module first bundled in 2.0)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1776944
NOTE: https://github.com/ansible/ansible/pull/65686
@@ -106942,7 +106941,6 @@ CVE-2019-14846 (Ansible, all ansible_engine-2.x versions and ansible_engine-3.x
{DLA-2202-1}
- ansible 2.8.6+dfsg-1 (low; bug #942188)
[buster] - ansible <no-dsa> (Minor issue)
- [stretch] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1755373
NOTE: https://github.com/ansible/ansible/pull/63366
NOTE: https://github.com/ansible/ansible/commit/90e74dd2600e5cc42dd9b4f4656f3d651c4ce5c4
@@ -121487,7 +121485,6 @@ CVE-2019-14856 (ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a
CVE-2019-10206 (ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2 ...)
- ansible 2.8.6+dfsg-1 (bug #933005)
[buster] - ansible <no-dsa> (Minor issue)
- [stretch] - ansible <no-dsa> (Minor issue)
[jessie] - ansible <not-affected> (Vulnerable code introduced later, password templating code introduced with 2.0 refactoring, '{{' supported in passwords)
NOTE: https://github.com/ansible/ansible/pull/59246
NOTE: 2.8.x https://github.com/ansible/ansible/pull/59552
@@ -121710,7 +121707,6 @@ CVE-2019-10156 (A flaw was discovered in the way Ansible templating was implemen
{DLA-1923-1}
- ansible 2.8.3+dfsg-1 (low; bug #930065)
[buster] - ansible <no-dsa> (Minor issue)
- [stretch] - ansible <no-dsa> (Minor issue)
NOTE: https://github.com/ansible/ansible/pull/57188
CVE-2019-10155 (The Libreswan Project has found a vulnerability in the processing of I ...)
- libreswan 3.27-6 (bug #930338)
@@ -234959,7 +234955,6 @@ CVE-2017-7482 (In the Linux kernel before version 4.12, Kerberos 5 tickets decod
NOTE: Fixed by: https://git.kernel.org/linus/5f2f97656ada8d811d3c1bef503ced266fcd53a0
CVE-2017-7481 (Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark loo ...)
- ansible 2.3.1.0+dfsg-1 (bug #862666)
- [stretch] - ansible <no-dsa> (Minor issue)
[jessie] - ansible <not-affected> (vulnerable code introduced in version 2.x)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1450018
NOTE: Fixed by: https://github.com/ansible/ansible/commit/ed56f51f185a1ffd7ea57130d260098686fcc7c2
=====================================
data/dla-needed.txt
=====================================
@@ -12,6 +12,8 @@ https://wiki.debian.org/LTS/Development#Triage_new_security_issues
To make it easier to see the entire history of an update, please append notes
rather than remove/replace existing ones.
+--
+ansible (Markus Koschany)
--
ceph (Emilio)
NOTE: 20200707: Vulnerable to at least CVE-2018-14662. (lamby)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3f661f3aac43d904e52bbaf68a05ed1b37cd240b...e183188e9d8c21ee1432f32573696f3d620120e3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3f661f3aac43d904e52bbaf68a05ed1b37cd240b...e183188e9d8c21ee1432f32573696f3d620120e3
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210127/53316ddb/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list