First published: Fri Apr 17 2015(Updated: )
`modules/chef.py` in SaltStack before 2014.7.4 does not properly handle files in `/tmp`.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/SaltStack | <2014.7.4 | 2014.7.4 |
pip/salt | <2014.7.4 | 2014.7.4 |
SaltStack Salt | <=2014.7.3 | |
Fedora | =23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1839 is considered to have a high severity due to its potential to expose sensitive information through improper file handling.
To fix CVE-2015-1839, upgrade SaltStack to version 2014.7.4 or later.
CVE-2015-1839 affects SaltStack versions prior to 2014.7.4 and certain Fedora systems.
CVE-2015-1839 was reported by Michael Scherer of Red Hat.
The main issue in CVE-2015-1839 is the insecure handling of files in the /tmp directory by SaltStack's chef.py module.