SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.html | vendor advisory release notes issue tracking |
http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.html | vendor advisory third party advisory release notes issue tracking |
http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.html | vendor advisory third party advisory release notes issue tracking |
https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5b | patch third party advisory issue tracking |
https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.html | vendor advisory release notes issue tracking |
https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.html | vendor advisory release notes issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=1500742 | third party advisory release notes issue tracking |