Fedora Linux 8579 Published by

A salt security update has been released for Fedora Linux 38.



[SECURITY] Fedora 38 Update: salt-3006.4-1.fc38


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-a6699df922
2023-11-08 01:38:49.724777
--------------------------------------------------------------------------------

Name : salt
Product : Fedora 38
Version : 3006.4
Release : 1.fc38
URL : https://saltproject.io/
Summary : A parallel remote execution system
Description :
Salt is a distributed remote execution system used to execute commands and
query data. It was developed in order to bring the best solutions found in
the world of remote execution together and make them better, faster and more
malleable. Salt accomplishes this via its ability to handle larger loads of
information, and not just dozens, but hundreds or even thousands of individual
servers, handle them quickly and through a simple and manageable interface.

--------------------------------------------------------------------------------
Update Information:

Fix for CVE-2023-34049
--------------------------------------------------------------------------------
ChangeLog:

* Mon Oct 30 2023 Gwyn Ciesla [gwync@protonmail.com] - 3006.4-1
- 3006.4
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2246812 - salt-3006.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2246812
[ 2 ] Bug #2246982 - CVE-2023-34049 salt: allows an attacker to force Salt-SSH to run their script [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2246982
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-a6699df922' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------