Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6849-1

Ubuntu Security Notice 6849-1 - It was discovered that Salt incorrectly validated method calls and sanitized paths. A remote attacker could possibly use this issue to access some methods without authentication.

Packet Storm
#vulnerability#ubuntu#auth
==========================================================================Ubuntu Security Notice USN-6849-1June 25, 2024salt vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 14.04 LTSSummary:Several security issues were fixed in Salt.Software Description:- salt: Infrastructure management built on a dynamic communication busDetails:It was discovered that Salt incorrectly validated method calls andsanitized paths. A remote attacker could possibly use this issue to accesssome methods without authentication. (CVE-2020-11651, CVE-2020-11652)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 14.04 LTS   salt-common                     0.17.5+ds-1ubuntu0.1~esm2                                   Available with Ubuntu Pro   salt-master                     0.17.5+ds-1ubuntu0.1~esm2                                   Available with Ubuntu Pro   salt-minion                     0.17.5+ds-1ubuntu0.1~esm2                                   Available with Ubuntu ProAfter a standard system update you need to restart Salt to make all thenecessary changes.References:   https://ubuntu.com/security/notices/USN-6849-1   CVE-2020-11651, CVE-2020-11652

Related news

CVE-2022-34456: DSA-2022-267: Dell EMC Metronode VS5 Security Update for Multiple Third-Party Component Vulnerabilities

Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application.

CVE-2022-34456: DSA-2022-267: Dell EMC Metronode VS5 Security Update for Multiple Third-Party Component Vulnerabilities

Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application.

CVE-2022-33923: DSA-2022-159: Dell PowerStore Family Security Update for Multiple Vulnerabilities

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.

CVE-2022-33923: DSA-2022-159: Dell PowerStore Family Security Update for Multiple Vulnerabilities

Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore underlying OS. Exploiting may lead to a system take over by an attacker.

Packet Storm: Latest News

Zeek 6.0.8