Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:3380-1

Опубликовано: 20 дек. 2017
Источник: suse-cvrf

Описание

Security update for Salt

This update for salt fixes one security issue and bugs.

The following security issues have been fixed:

  • CVE-2017-14695: A directory traversal vulnerability in minion id validation allowed remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. (bsc#1062462)
  • CVE-2017-14696: It was possible to force a remote Denial of Service with a specially crafted authentication request. (bsc#1062464)

Additionally, the following non-security issues have been fixed:

  • Removed deprecation warning for beacon configuration using dictionaries. (bsc#1041993)
  • Fixed beacons failure when pillar-based suppressing config-based. (bsc#1060230)
  • Fixed minion resource exhaustion when many functions are being executed in parallel. (bsc#1059758)
  • Remove 'TasksTask' attribute from salt-master.service in older versions of systemd. (bsc#985112)
  • Fix for delete_deployment in Kubernetes module. (bsc#1059291)
  • Catching error when PIDfile cannot be deleted. (bsc#1050003)
  • Use $HOME to get the user home directory instead using '~' char. (bsc#1042749)

Список пакетов

SUSE Enterprise Storage 3
salt-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Enterprise Storage 4
salt-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Enterprise Storage 5
salt-2016.11.4-46.10.1
salt-api-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Linux Enterprise Module for Advanced Systems Management 12
salt-2016.11.4-46.10.1
salt-api-2016.11.4-46.10.1
salt-bash-completion-2016.11.4-46.10.1
salt-cloud-2016.11.4-46.10.1
salt-doc-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
salt-proxy-2016.11.4-46.10.1
salt-ssh-2016.11.4-46.10.1
salt-syndic-2016.11.4-46.10.1
salt-zsh-completion-2016.11.4-46.10.1
SUSE Linux Enterprise Point of Sale 12 SP2
salt-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Manager Client Tools 12
salt-2016.11.4-46.10.1
salt-doc-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Manager Proxy 3.0
salt-2016.11.4-46.10.1
salt-api-2016.11.4-46.10.1
salt-bash-completion-2016.11.4-46.10.1
salt-doc-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
salt-proxy-2016.11.4-46.10.1
salt-ssh-2016.11.4-46.10.1
salt-syndic-2016.11.4-46.10.1
salt-zsh-completion-2016.11.4-46.10.1
SUSE Manager Proxy 3.1
salt-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
SUSE Manager Server 3.0
salt-2016.11.4-46.10.1
salt-api-2016.11.4-46.10.1
salt-bash-completion-2016.11.4-46.10.1
salt-doc-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
salt-proxy-2016.11.4-46.10.1
salt-ssh-2016.11.4-46.10.1
salt-syndic-2016.11.4-46.10.1
salt-zsh-completion-2016.11.4-46.10.1
SUSE Manager Server 3.1
salt-2016.11.4-46.10.1
salt-api-2016.11.4-46.10.1
salt-bash-completion-2016.11.4-46.10.1
salt-cloud-2016.11.4-46.10.1
salt-doc-2016.11.4-46.10.1
salt-master-2016.11.4-46.10.1
salt-minion-2016.11.4-46.10.1
salt-proxy-2016.11.4-46.10.1
salt-ssh-2016.11.4-46.10.1
salt-syndic-2016.11.4-46.10.1
salt-zsh-completion-2016.11.4-46.10.1

Описание

Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.


Затронутые продукты
SUSE Enterprise Storage 3:salt-2016.11.4-46.10.1
SUSE Enterprise Storage 3:salt-master-2016.11.4-46.10.1
SUSE Enterprise Storage 3:salt-minion-2016.11.4-46.10.1
SUSE Enterprise Storage 4:salt-2016.11.4-46.10.1

Ссылки

Описание

SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.


Затронутые продукты
SUSE Enterprise Storage 3:salt-2016.11.4-46.10.1
SUSE Enterprise Storage 3:salt-master-2016.11.4-46.10.1
SUSE Enterprise Storage 3:salt-minion-2016.11.4-46.10.1
SUSE Enterprise Storage 4:salt-2016.11.4-46.10.1

Ссылки
Уязвимость SUSE-SU-2017:3380-1