Candidate: CVE-2014-4659 PublicDate: 2020-02-20 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4659 http://www.openwall.com/lists/oss-security/2014/06/26/19 Description: Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [5.5 MEDIUM] Patches_ansible: upstream: https://github.com/ansible/ansible/commit/c4b5e46054c74176b2446c82d4df1a2610eddc08 upstream_ansible: released (1.5.5+dfsg-1) lucid_ansible: DNE precise_ansible: DNE precise/esm_ansible: DNE saucy_ansible: ignored (reached end-of-life) trusty_ansible: ignored (out of standard support) trusty/esm_ansible: not-affected (1.5.4+dfsg-1) utopic_ansible: not-affected (1.6.5+dfsg-1) vivid_ansible: not-affected (1.6.5+dfsg-1) vivid/stable-phone-overlay_ansible: DNE vivid/ubuntu-core_ansible: DNE wily_ansible: not-affected (1.6.5+dfsg-1) xenial_ansible: not-affected (1.6.5+dfsg-1) yakkety_ansible: not-affected (1.6.5+dfsg-1) zesty_ansible: not-affected (1.6.5+dfsg-1) artful_ansible: not-affected (1.6.5+dfsg-1) bionic_ansible: not-affected (1.6.5+dfsg-1) cosmic_ansible: not-affected (1.6.5+dfsg-1) disco_ansible: not-affected (1.6.5+dfsg-1) devel_ansible: not-affected (1.6.5+dfsg-1)