LWN.net Logo

Fedora alert FEDORA-2013-15169 (ansible)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 19 Update: ansible-1.2.3-2.fc19
Date:  Fri, 30 Aug 2013 23:03:44 +0000
Message-ID:  <20130830230344.1260E21809@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-15169 2013-08-22 22:35:56 -------------------------------------------------------------------------------- Name : ansible Product : Fedora 19 Version : 1.2.3 Release : 2.fc19 URL : http://ansibleworks.com Summary : SSH-based configuration management, deployment, and task execution system Description : Ansible is a radically simple model-driven configuration management, multi-node deployment, and remote task execution system. Ansible works over SSH and does not require any software or daemons to be installed on remote nodes. Extension modules can be written in any language and are transferred to managed machines automatically. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2013-4260 and CVE-2013-4259 See: https://groups.google.com/forum/#!topic/ansible-project/U... for more information. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 21 2013 Kevin Fenzi <kevin@scrye.com> 1.2.3-2 - Update to 1.2.3 - Fixes CVE-2013-4260 and CVE-2013-4259 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Sat Jul 6 2013 Kevin Fenzi <kevin@scrye.com> 1.2.2-1 - Update to 1.2.2 with minor fixes * Fri Jul 5 2013 Kevin Fenzi <kevin@scrye.com> 1.2.1-2 - Update to newer upstream re-release to fix a syntax error * Thu Jul 4 2013 Kevin Fenzi <kevin@scrye.com> 1.2.1-1 - Update to 1.2.1 - Fixes CVE-2013-2233 * Mon Jun 10 2013 Kevin Fenzi <kevin@scrye.com> 1.2-1 - Update to 1.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #998223 - CVE-2013-4259 ansible: insecure location for ssh ControlMaster socket https://bugzilla.redhat.com/show_bug.cgi?id=998223 [ 2 ] Bug #998227 - CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory https://bugzilla.redhat.com/show_bug.cgi?id=998227 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ansible' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds