Debian Security Advisory

DLA-1576-1 ansible -- LTS security update

Date Reported:
12 Nov 2018
Affected Packages:
ansible
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-16837.
More information:

It was discovered that there was a potential SSH passphrase disclosure vulnerability in the ansible configuration management system,

The User module leaked data that was passed as a parameter to the ssh-keygen(1) utility, thus revealing any credentials in cleartext form in the global process list.

For Debian 8 Jessie, this issue has been fixed in ansible version 1.7.2+dfsg-2+deb8u1.

We recommend that you upgrade your ansible packages.