Key management errors in Ansible - CVE-2016-8614
Published: July 31, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Proxy Module
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
POS_Image-JeOS7
POS_Image-Graphical7
dracut-saltboot
golang-github-prometheus-promu
ansible
ansible-doc
ansible-test
spacewalk-koan
python3-spacewalk-koan
mgr-daemon
python3-uyuni-common-libs
uyuni-proxy-systemd-services
spacewalk-client-setup
python3-spacewalk-check
python3-spacewalk-client-tools
spacewalk-check
spacewalk-client-tools
python3-spacewalk-client-setup
spacecmd
grafana-debuginfo
grafana
How to mitigate CVE-2016-8614
POS_Image-JeOS7 - update to 0.1.1710765237.46af599-150000.1.21.2
POS_Image-Graphical7 - update to 0.1.1710765237.46af599-150000.1.21.2
dracut-saltboot - update to 0.1.1710765237.46af599-150000.1.53.2
golang-github-prometheus-promu - update to 0.14.0-150000.3.18.2
ansible - addressed in versions 2.2.0.0-2.el6, 2.2.0.0-2.el7, 2.2.0.0-2.fc24, 2.2.0.0-2.fc25, 2.2.0.0-3.el6, 2.2.0.0-3.el7, 2.2.0.0-3.fc24, 2.2.0.0-3.fc25
ansible - update to 2.9.27-150000.1.17.2
ansible-doc - update to 2.9.27-150000.1.17.2
ansible-test - update to 2.9.27-150000.1.17.2
spacewalk-koan - update to 4.3.6-150000.3.33.2
python3-spacewalk-koan - update to 4.3.6-150000.3.33.2
mgr-daemon - update to 4.3.9-150000.1.47.2
python3-uyuni-common-libs - update to 4.3.10-150000.1.39.2
uyuni-proxy-systemd-services - update to 4.3.12-150000.1.21.2
spacewalk-client-setup - update to 4.3.19-150000.3.89.2
python3-spacewalk-check - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-tools - update to 4.3.19-150000.3.89.2
spacewalk-check - update to 4.3.19-150000.3.89.2
spacewalk-client-tools - update to 4.3.19-150000.3.89.2
python3-spacewalk-client-setup - update to 4.3.19-150000.3.89.2
spacecmd - update to 4.3.27-150000.3.116.2
grafana-debuginfo - update to 9.5.18-150000.1.63.2
grafana - update to 9.5.18-150000.1.63.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Ansible
- SUSE update for SUSE Manager Client Tools
- Fedora 24 update for ansible
- Fedora 25 update for ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora EPEL 6 update for ansible
- Fedora EPEL 7 update for ansible
- Fedora 24 update for ansible
- Fedora 25 update for ansible