Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.131289
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2016-0163)
Resumen:The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2016-0163 advisory.
Descripción:Summary:
The remote host is missing an update for the 'ansible' package(s) announced via the MGASA-2016-0163 advisory.

Vulnerability Insight:
Updated ansible package fixes security vulnerability:

A vulnerability in lxc_container, ansible module, was found allowing to get
root inside the container. The problem is in the create_script function, which
tries to write to /opt/.lxc-attach-script inside of the container. If the
attacker can write to /opt/.lxc-attach-script before that, he can overwrite
arbitrary files or execute commands as root (CVE-2016-3096).

Affected Software/OS:
'ansible' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2016-3096
FEDORA-2016-28ff51a3f5
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183103.html
FEDORA-2016-65519440f5
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183132.html
FEDORA-2016-679c4ddd3c
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/184175.html
FEDORA-2016-ab154c56dd
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183252.html
FEDORA-2016-cd3cf8e7d0
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183274.html
GLSA-201607-14
https://security.gentoo.org/glsa/201607-14
[ansible-announce] 20160415 Ansible 1.9.6-1 has been released
https://groups.google.com/forum/#%21topic/ansible-announce/tqiZbcWxYig
[ansible-announce] 20160419 Ansible 2.0.2.0 has been released
https://groups.google.com/forum/#%21topic/ansible-announce/E80HLZilTU0
https://bugzilla.redhat.com/show_bug.cgi?id=1322925
https://github.com/ansible/ansible-modules-extras/pull/1941
https://github.com/ansible/ansible-modules-extras/pull/1941/commits/8c6fe646ee79f5e55361b885b7efed5bec72d4a4
https://github.com/ansible/ansible/blob/v1.9.6-1/CHANGELOG.md#196-dancing-in-the-street---tbd
https://github.com/ansible/ansible/blob/v2.0.2.0-1/CHANGELOG.md#202-over-the-hills-and-far-away
CopyrightCopyright (C) 2016 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.