Ubuntu Security Update USN-8153-1: Salt vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,748
Reaction score
74
Credits
-1,257
Zach Malone discovered that Salt did not properly handle permissions to cache data. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2015-8034) Dylan Frese discovered that Salt incorrectly allowed users to specify PAM service. An attacker could possibly use this issue to bypass authentication. (CVE-2016-3176)

Continue reading...
 


That could've been real bad. At least it's more secure than windows and NPM.
 


Follow Linux.org

Members online


Top