Candidate: CVE-2015-1838 PublicDate: 2017-04-13 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1838 https://github.com/saltstack/salt/commit/e11298d7155e9982749483ca5538e46090caef9c Description: modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp. Ubuntu-Description: Notes: debian> Vulnerable code only present in experimental version; introduced in 2014.7.0 Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L [5.3 MEDIUM] Patches_salt: upstream_salt: released (2014.1.13+ds-3) lucid_salt: DNE precise_salt: DNE precise/esm_salt: DNE trusty_salt: not-affected (code not present) trusty/esm_salt: DNE (trusty was not-affected [code not present]) utopic_salt: ignored (reached end-of-life) vivid_salt: ignored (reached end-of-life) vivid/stable-phone-overlay_salt: DNE vivid/ubuntu-core_salt: DNE wily_salt: ignored (reached end-of-life) xenial_salt: not-affected (2015.8.8+ds-1) yakkety_salt: ignored (reached end-of-life) zesty_salt: ignored (reached end-of-life) artful_salt: ignored (reached end-of-life) bionic_salt: not-affected (2015.8.8+ds-1) devel_salt: not-affected (2015.8.8+ds-1)