Candidate: CVE-2015-6240 PublicDate: 2017-06-07 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6240 http://www.openwall.com/lists/oss-security/2015/07/14/3 Description: The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack. Ubuntu-Description: Notes: tyhicks> Fixed upstream in 1.9.2 Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_ansible: upstream_ansible: released (1.9.2+dfsg-1) precise_ansible: DNE precise/esm_ansible: DNE trusty_ansible: ignored (out of standard support) trusty/esm_ansible: needed vivid_ansible: ignored (reached end-of-life) vivid/stable-phone-overlay_ansible: DNE vivid/ubuntu-core_ansible: DNE wily_ansible: not-affected (1.9.2+dfsg-2) xenial_ansible: not-affected (1.9.2+dfsg-2) yakkety_ansible: not-affected (1.9.2+dfsg-2) zesty_ansible: not-affected (1.9.2+dfsg-2) artful_ansible: not-affected (1.9.2+dfsg-2) bionic_ansible: not-affected (1.9.2+dfsg-2) cosmic_ansible: not-affected (1.9.2+dfsg-2) disco_ansible: not-affected (1.9.2+dfsg-2) eoan_ansible: not-affected (1.9.2+dfsg-2) focal_ansible: not-affected (1.9.2+dfsg-2) groovy_ansible: not-affected (1.9.2+dfsg-2) hirsute_ansible: not-affected (1.9.2+dfsg-2) impish_ansible: not-affected (1.9.2+dfsg-2) jammy_ansible: not-affected (1.9.2+dfsg-2) devel_ansible: not-affected (1.9.2+dfsg-2)