Bug 980821 (CVE-2013-2233)

Summary: CVE-2013-2233 ansible: Does not cache SSH host keys (preventing possibility of server's host key to be checked against system host keys)
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: kevin, maxim
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-05-12 07:03:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 980827, 980828    
Bug Blocks:    

Description Jan Lieskovsky 2013-07-03 10:01:36 UTC
A security flaw was found in the way Ansible, a SSH-based configuration management, deployment, and task execution system, performed remote server's SSH host key management (previously ability to store known SSH server's host keys to local cache was not supported). A remote attacker could use this flaw to conduct man-in-the-middle (MiTM) attacks against the Ansible task execution system user.

References:
[1] http://www.openwall.com/lists/oss-security/2013/07/01/2
[2] http://www.openwall.com/lists/oss-security/2013/07/02/6

Upstream bug (no upstream patch as of 2013-07-03):
[3] https://github.com/ansible/ansible/issues/857

Comment 1 Jan Lieskovsky 2013-07-03 10:04:59 UTC
This issue affects the versions of the ansible package, as shipped with Fedora release of 17, 18, and 19. Please schedule an update (once there's final upstream patch available).

--

This issue affects the version of the ansible package, as shipped with Fedora EPEL-6. Please schedule an update (once there's final upstream patch available).

Comment 2 Jan Lieskovsky 2013-07-03 10:06:53 UTC
Created ansible tracking bugs for this issue:

Affects: fedora-all [bug 980827]
Affects: epel-6 [bug 980828]

Comment 3 Fedora Update System 2013-07-15 01:04:52 UTC
ansible-1.2.2-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2013-07-15 01:06:18 UTC
ansible-1.2.2-1.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Fedora Update System 2013-07-15 01:10:03 UTC
ansible-1.2.2-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2013-07-21 18:37:17 UTC
ansible-1.2.2-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.