Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8614

Опубликовано: 31 июл. 2018
Источник: debian

Описание

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ansiblefixed2.2.0.0-1package
ansiblenot-affectedjessiepackage

Примечания

  • Fixed upstream in v2.2.0.0-1

  • https://github.com/ansible/ansible-modules-core/issues/5237

  • https://github.com/ansible/ansible-modules-core/pull/5353

  • https://github.com/ansible/ansible-modules-core/pull/5357

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 7 лет назад

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

CVSS3: 6.3
redhat
больше 9 лет назад

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

CVSS3: 6.3
nvd
больше 7 лет назад

A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

CVSS3: 7.5
github
больше 7 лет назад

Ansible apt_key module does not properly verify key fingerprint

suse-cvrf
почти 2 года назад

Security update for SUSE Manager Client Tools