Sync ansible 2.8.3+dfsg-1 (universe) from Debian unstable (main)

Bug #1839312 reported by Jean-Louis Dupond
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
ansible (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Please sync ansible 2.8.3+dfsg-1 (universe) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: Sensitive information could be exposed to remote node.
    - debian/patches/CVE-2019-10156-1.patch: Don't pass locals.
    - debian/patches/CVE-2019-10156-2.patch: Fixed tests.
    - CVE-2019-10156

-> Security fix is in newest debian version

Changelog entries since current eoan version 2.7.8+dfsg-1ubuntu1:

ansible (2.8.3+dfsg-1) unstable; urgency=medium

  * New upstream release (Closes: #932288)
  * This release fixes CVE-2019-10156 (Closes: #930065)

 -- Lee Garrett <email address hidden> Thu, 01 Aug 2019 10:39:19 -0300

CVE References

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in ansible (Ubuntu):
status: New → Confirmed
Revision history for this message
Rik Mills (rikmills) wrote :

2.8.3+dfsg-1 in Debian causes autopkgtest regression for ansible-lint on debian CI.

https://ci.debian.net/packages/a/ansible-lint/unstable/amd64/

we have the same ansible-lint, so seems likely if this was synced it would get stuck in eoan-proposed for now.

Revision history for this message
Rik Mills (rikmills) wrote :

This bug was fixed in the package ansible - 2.8.3+dfsg-1

---------------
ansible (2.8.3+dfsg-1) unstable; urgency=medium

  * New upstream release (Closes: #932288)
  * This release fixes CVE-2019-10156 (Closes: #930065)

 -- Lee Garrett <email address hidden> Thu, 01 Aug 2019 10:39:19 -0300

Changed in ansible (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.