Ansible: Privilege escalation Multiple vulnerabilities has been found in Ansible which may allow local privilege escalation. ansible 2014-11-23 2014-11-23: 1 516564 517770 local 1.6.8 1.6.8

Ansible is a radically simple IT automation platform.

Multiple vulnerabilities have been discovered in Ansible. Please review the CVE identifiers referenced below for details.

A local attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or obtain sensitive information.

There is no known workaround at this time.

All Ansible users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-admin/ansible-1.6.8"
CVE-2014-4657 CVE-2014-4678 CVE-2014-4966 CVE-2014-4967 pinkbyte ackle