Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1866

Опубликовано: 12 апр. 2016
Источник: debian
EPSS Низкий

Описание

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
saltfixed2015.8.5+ds-1package
saltnot-affectedjessiepackage

Примечания

  • https://docs.saltstack.com/en/latest/topics/releases/2015.8.5.html

EPSS

Процентиль: 72%
0.01516
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

redhat
больше 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

CVSS3: 8.1
nvd
больше 10 лет назад

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

suse-cvrf
больше 10 лет назад

Security update for salt

CVSS3: 8.1
github
больше 4 лет назад

Salt Improper Access Control

EPSS

Процентиль: 72%
0.01516
Низкий
Уязвимость CVE-2016-1866