CVE-2013-4260

Publication date 16 September 2013

Last updated 24 July 2024


Ubuntu priority

lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in /var/tmp/ansible/.

Status

Package Ubuntu Release Status
ansible 14.04 LTS trusty
Not affected
13.10 saucy Ignored end of life
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Not in release