CVE-2015-1838
MEDIUM severity · CVSS 5.3 · CWE-19
5.3CVSS MEDIUM
Summary
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactLow
Integrity impactLow
Availability impactLow
Exploit probability (EPSS)0%
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://bugzilla.redhat.com/show_bug.cgi?id=1212784 ↗
Additional information
- NVD record
- https://bugzilla.redhat.com/show_bug.cgi?id=1212784Patch
- https://github.com/saltstack/salt/commit/e11298d7155e9982749483ca5538e46090caef9cPatch
- https://docs.saltstack.com/en/latest/topics/releases/2014.7.4.htmlAdvisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175568.htmlAdvisory