First published: Fri Apr 17 2015(Updated: )
`modules/serverdensity_device.py` in SaltStack before 2014.7.4 does not properly handle files in `/tmp`.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/salt | <2014.7.4 | 2014.7.4 |
redhat/SaltStack | <2014.7.4 | 2014.7.4 |
SaltStack Salt | <=2014.7.3 | |
Fedora | =23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1838 is considered a moderate severity vulnerability due to its improper handling of temporary files.
To fix CVE-2015-1838, upgrade SaltStack to version 2014.7.4 or later.
SaltStack versions prior to 2014.7.4 are affected by CVE-2015-1838.
CVE-2015-1838 was reported by Michael Scherer of Red Hat.
The vulnerable code for CVE-2015-1838 is located in the `modules/serverdensity_device.py` file in SaltStack.