|
|
Log in / Subscribe / Register

Mageia alert MGASA-2019-0234 (ansible)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2019-0234: Updated ansible packages fix security vulnerability
Date:  Sat, 31 Aug 2019 15:23:48 +0200
Message-ID:  <20190831132348.728D49F640@duvel.mageia.org>

MGASA-2019-0234 - Updated ansible packages fix security vulnerability Publication date: 31 Aug 2019 URL: https://advisories.mageia.org/MGASA-2019-0234.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-10156 Description: Updated ansible package fixes security vulnerability: A flaw was discovered in the way Ansible templating was implemented before version 2.7.12, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed (CVE-2019-10156). Also, python-jmespath was added as a new dependency in Mageia 6. References: - https://bugs.mageia.org/show_bug.cgi?id=25285 - https://github.com/ansible/ansible/blob/stable-2.7/change... - https://usn.ubuntu.com/4072-1/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1... SRPMS: - 7/core/ansible-2.7.12-1.mga7 - 6/core/ansible-2.7.12-1.mga6 - 6/core/python-jmespath-0.9.4-1.2.mga6


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds