[USN-4072-1] Ansible vulnerabilities

Paulo Flabiano Smorigo pfsmorigo at canonical.com
Thu Jul 25 00:27:22 UTC 2019

Ubuntu Security Notice USN-4072-1
July 24, 2019

ansible vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS


Several security issues were fixed in Ansible.

Software Description:
- ansible: Configuration management, deployment, and task execution system


It was discovered that Ansible failed to properly handle sensitive information.
A local attacker could use those vulnerabilities to extract them.

It was discovered that Ansible could load configuration files from the current
working directory containing crafted commands. An attacker could run arbitrary
code as result.

It was discovered that Ansible fetch module had a path traversal vulnerability.
A local attacker could copy and overwrite files outside of the specified

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
  ansible                         2.7.8+dfsg-1ubuntu0.19.04.1

Ubuntu 18.04 LTS:
  ansible                         2.5.1+dfsg-1ubuntu0.1

Ubuntu 16.04 LTS:

In general, a standard system update will make all the necessary changes.

  CVE-2017-7481, CVE-2018-10855, CVE-2018-10874, CVE-2018-10875,
  CVE-2018-16837, CVE-2018-16876, CVE-2019-10156, CVE-2019-3828

Package Information:
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20190724/0b778cae/attachment.sig>

More information about the ubuntu-security-announce mailing list