CVE-2013-4260
published 2013-09-16CVE-2013-4260: lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via…
PriorityP48low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.33%
25.1th percentile
lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in /var/tmp/ansible/.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ansible | — | — |
| redhat | ansible | — | — |
| redhat | ansible | — | — |
| redhat | ansible | — | — |
| redhat | ansible | >= 1.2 < 1.2.3 | 1.2.3 |
| redhat | ansible | >= 1.2.0 < 1.2.3 | 1.2.3 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-4260: ansible - lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook do...
vendor_debian·2013·CVSS 3.3
CVE-2013-4260 [LOW] CVE-2013-4260: ansible - lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook do...
lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in /var/tmp/ansible/.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Ansible Arbitrary File Overwrite Vulnerability
osv·2022-05-14
CVE-2013-4260 [MEDIUM] Ansible Arbitrary File Overwrite Vulnerability
Ansible Arbitrary File Overwrite Vulnerability
`lib/ansible/playbook/__init__.py` in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in `/var/tmp/ansible/`.
GHSA
Ansible Arbitrary File Overwrite Vulnerability
ghsa·2022-05-14
CVE-2013-4260 [MEDIUM] CWE-281 Ansible Arbitrary File Overwrite Vulnerability
Ansible Arbitrary File Overwrite Vulnerability
`lib/ansible/playbook/__init__.py` in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in `/var/tmp/ansible/`.
OSV
CVE-2013-4260: lib/ansible/playbook/__init__
osv·2013-09-16
CVE-2013-4260 CVE-2013-4260: lib/ansible/playbook/__init__
lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local users to overwrite arbitrary files via a symlink attack on a retry file with a predictable name in /var/tmp/ansible/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4259 CVE-2013-4260 ansible: various flaws [fedora-all]
bugzilla·2013-08-21·CVSS 1.9
CVE-2013-4259 [LOW] CVE-2013-4259 CVE-2013-4260 ansible: various flaws [fedora-all]
CVE-2013-4259 CVE-2013-4260 ansible: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple
Bugzilla
CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory [epel-6]
bugzilla·2013-08-21·CVSS 3.3
CVE-2013-4260 [LOW] CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory [epel-6]
CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory
bugzilla·2013-08-18·CVSS 3.3
CVE-2013-4260 [LOW] CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory
CVE-2013-4260 ansible: predictible filename used for failed result in world writable directory
Since version 1.2 of ansible, failed run ( due to connexion errors, or config error ) are listed into /var/tmp/ansible/$script_name.yml , with $script_name being the script name used ( or rather the playbook, in ansible linguo )
There is no verification on the file or directory here, and /var/tmp is world writable.
Worst, due to it using a subdirectory under /var/tmp, some symlink protection may not apply ( not tested ). For example, if i create a directory /var/tmp/ansible with owner misc:users and a symlink to a file of joe, the kernel would permit to follow since the symlink and owner of the directory match. This permit to erase file content among others. I am not sure what kind of specific
http://www.ansible.com/securityhttps://bugzilla.redhat.com/show_bug.cgi?id=998227https://exchange.xforce.ibmcloud.com/vulnerabilities/86898https://groups.google.com/forum/#%21topic/ansible-project/UVDYW0HGcNghttp://www.ansible.com/securityhttps://bugzilla.redhat.com/show_bug.cgi?id=998227https://exchange.xforce.ibmcloud.com/vulnerabilities/86898https://groups.google.com/forum/#%21topic/ansible-project/UVDYW0HGcNg
2013-09-16
Published