Candidate: CVE-2014-4657 PublicDate: 2020-02-20 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4657 https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c http://www.openwall.com/lists/oss-security/2014/06/26/19 https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md Description: The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_ansible: upstream: https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c upstream_ansible: released (1.5.5+dfsg-1) lucid_ansible: DNE precise_ansible: DNE precise/esm_ansible: DNE saucy_ansible: ignored (reached end-of-life) trusty_ansible: ignored (out of standard support) trusty/esm_ansible: not-affected (1.5.4+dfsg-1) utopic_ansible: not-affected (1.6.5+dfsg-1) vivid_ansible: not-affected (1.6.5+dfsg-1) vivid/stable-phone-overlay_ansible: DNE vivid/ubuntu-core_ansible: DNE wily_ansible: not-affected (1.6.5+dfsg-1) xenial_ansible: not-affected (1.6.5+dfsg-1) yakkety_ansible: not-affected (1.6.5+dfsg-1) zesty_ansible: not-affected (1.6.5+dfsg-1) artful_ansible: not-affected (1.6.5+dfsg-1) bionic_ansible: not-affected (1.6.5+dfsg-1) cosmic_ansible: not-affected (1.6.5+dfsg-1) disco_ansible: not-affected (1.6.5+dfsg-1) devel_ansible: not-affected (1.6.5+dfsg-1)