CVE-2016-3176
31.01.2017, 19:59
Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.Enginsight
Vendor | Product | Version |
---|---|---|
saltstack | salt | 𝑥 ≤ 2015.5.9 |
saltstack | salt | 2015.8.0 |
saltstack | salt | 2015.8.1 |
saltstack | salt | 2015.8.2 |
saltstack | salt | 2015.8.3 |
saltstack | salt | 2015.8.4 |
saltstack | salt | 2015.8.5 |
saltstack | salt | 2015.8.7 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration