Mageia 2019-0114: ansible security update
Summary
The user module leaked parameters passed to ssh-keygen to the process
environment (CVE-2018-16837).
The fetch module was susceptible to path traversal (CVE-2019-3828).
References
- https://bugs.mageia.org/show_bug.cgi?id=24395
- https://www.debian.org/security/2019/dsa-4396
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3828
Resolution
MGASA-2019-0114 - Updated ansible packages fix security vulnerability
SRPMS
- 6/core/ansible-2.4.6.0-1.3.mga6