Date: Thu, 21 Aug 2014 10:44:55 -0600 From: "C. R. Oldham" <cr@...tstack.com> To: oss-security@...ts.openwall.com Subject: Revised: Salt 2014.1.10 released Greetings, We are pleased to announce the 2014.1.10 release of Salt. The release notes can be found here: http://docs.saltstack.com/en/latest/topics/releases/2014.1.10.html The sources are available on pypi: https://pypi.python.org/pypi/salt/2014.1.10 Salt 2014.1.10 fixes security issues documented by CVE-2014-3563: Insecure tmp-file creation in seed.py, salt-ssh, and salt-cloud. Upgrading is recommended. Special thanks to Kurt Seifried at Red Hat for investigating these issues and bringing them to our attention (and also letting me know that my first post got mangled somehow). -- C. R. Oldham, Platform Engineer, SaltStack, Inc. 801-564-4673 / cr@...tstack.com / https://github.com/cro [ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ