First published: Fri Aug 22 2014(Updated: )
Last updated 24 July 2024
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SaltStack Salt | <=2014.1.9 | |
pip/salt | <2014.1.10 | 2014.1.10 |
debian/salt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3563 is considered to have unspecified severity, as it affects multiple vulnerabilities related to local user permissions and temporary file creation.
To fix CVE-2014-3563, upgrade to Salt version 2014.1.10 or later.
CVE-2014-3563 affects all SaltStack versions before 2014.1.10.
CVE-2014-3563 includes vulnerabilities related to temporary file creation in seed.py, salt-ssh, and salt-cloud.
Local users may exploit CVE-2014-3563 to achieve unspecified impacts on the system.