MGASA-2017-0164
Advisory lineage Upstream: 3 Downstream: 0
Published: 10 Jun 2017, 07:01
Last modified:16 Apr 2026, 06:25
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
10 Jun 2017, 07:01
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated
Description
Updated ansible packages fix security vulnerability It was found that apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key (CVE-2016-8614). It is reported that in Ansible, under some circumstances the mysql_user module may fail to correctly change a password. Thus an old password may still be active when it should have been changed (CVE-2016-8647). Data for lookup plugins used as variables was not being correctly marked as "unsafe" (CVE-2017-7481). The ansible package has been updated to version 2.3.1 to fix these issues and several other bugs.
Affected Systems
- mageia•ansible
< 2.3.1.0-2.mga5
References (6)
- https://advisories.mageia.org/MGASA-2017-0164.html
- https://bugs.mageia.org/show_bug.cgi?id=19740
- https://github.com/ansible/ansible/blob/stable-2.3/CHANGELOG.md
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BTRG5RQTE7EPZLVJR7WCHPV2O3LCCEJ5/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/WJGWOHRWU3FB2DF3V6NNS4GGBWKSOWYA/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/UQMRFYTFTPAGI22UEXIEZH4U4BOTGVWH