Bug 1388038 (CVE-2016-8614)

Summary: CVE-2016-8614 ansible: Improper verification of key fingerprints in apt_key module
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aortega, apevec, arubin, ayoung, bleanhar, ccoleman, chrisw, cvsbot-xmlrpc, dedgar, dmcphers, edube, gmollett, jgoulding, jialiu, jjoyce, jkeck, jmatthew, joelsmith, jokerman, jschluet, kbasil, kseifried, lhh, lmeyer, lpeer, markmc, mmccomas, nthomas, rbryant, sankarshan, sclewis, security-response-team, sgirijan, sisharma, slinaber, smallamp, smohan, ssaha, tcarlin, tdawson, tdecacqu, tsanders, tvignaud, vbellur
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20161101,reported=20161021,source=researcher,cvss2=6.8/AV:N/AC:M/Au:N/C:P/I:P/A:P,cvss3=6.3/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L,cwe=CWE-358,rhscon-2/ansible=notaffected,rhes-3.0/ansible=notaffected,openshift-enterprise-3/ansible=notaffected,qci-1/ansible=notaffected,openstack-10/ansible=notaffected,fedora-all/ansible=affected,fedora-all/ansible1.9=affected,epel-all/ansible=affected,epel-all/ansible1.9=affected
Fixed In Version: ansible 2.2.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-01 15:28:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1388661, 1390650, 1390651, 1390652, 1390653    
Bug Blocks: 1388042    

Description Adam Mariš 2016-10-24 09:53:58 UTC
It was found that apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

Upstream bug:

https://github.com/ansible/ansible-modules-core/issues/5237

Upstream patches:

https://github.com/ansible/ansible-modules-core/pull/5353
https://github.com/ansible/ansible-modules-core/pull/5357

Comment 4 Kurt Seifried 2016-11-01 15:25:41 UTC
Created ansible1.9 tracking bugs for this issue:

Affects: fedora-all [bug 1390651]
Affects: epel-all [bug 1390653]

Comment 5 Kurt Seifried 2016-11-01 15:26:01 UTC
Created ansible tracking bugs for this issue:

Affects: fedora-all [bug 1390650]
Affects: epel-all [bug 1390652]

Comment 6 Kurt Seifried 2016-11-01 15:28:42 UTC
This issue is addressed in Ansible 2.2.0 available at:

https://github.com/ansible/ansible/releases/tag/v2.2.0.0-1