--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-ac1aa963e4
2023-09-14 00:42:52.692906
--------------------------------------------------------------------------------

Name        : salt
Product     : Fedora 37
Version     : 3005.2
Release     : 1.fc37
URL         : https://saltproject.io/
Summary     : A parallel remote execution system
Description :
Salt is a distributed remote execution system used to execute commands and
query data. It was developed in order to bring the best solutions found in
the world of remote execution together and make them better, faster and more
malleable. Salt accomplishes this via its ability to handle larger loads of
information, and not just dozens, but hundreds or even thousands of individual
servers, handle them quickly and through a simple and manageable interface.

--------------------------------------------------------------------------------
Update Information:

Fixes for CVE-2023-20897 and CVE-2023-20898
--------------------------------------------------------------------------------
ChangeLog:

* Tue Sep  5 2023 Gwyn Ciesla  - 3005.2-1
- 3005.2
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2237512 - CVE-2023-20898 salt: Git Providers can read from the wrong environment [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2237512
  [ 2 ] Bug #2237514 - CVE-2023-20897 salt: DOS in minion return [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2237514
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-ac1aa963e4' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 37: salt 2023-ac1aa963e4

September 14, 2023
Fixes for CVE-2023-20897 and CVE-2023-20898

Summary

Salt is a distributed remote execution system used to execute commands and

query data. It was developed in order to bring the best solutions found in

the world of remote execution together and make them better, faster and more

malleable. Salt accomplishes this via its ability to handle larger loads of

information, and not just dozens, but hundreds or even thousands of individual

servers, handle them quickly and through a simple and manageable interface.

Update Information:

Fixes for CVE-2023-20897 and CVE-2023-20898

Change Log

* Tue Sep 5 2023 Gwyn Ciesla - 3005.2-1 - 3005.2

References

[ 1 ] Bug #2237512 - CVE-2023-20898 salt: Git Providers can read from the wrong environment [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237512 [ 2 ] Bug #2237514 - CVE-2023-20897 salt: DOS in minion return [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2237514

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ac1aa963e4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
Name : salt
Product : Fedora 37
Version : 3005.2
Release : 1.fc37
URL : https://saltproject.io/
Summary : A parallel remote execution system

Related News