Subject: CVS commit: pkgsrc/sysutils/salt
From: Thomas Klausner
Date: 2015-12-11 01:27:07
Message id: 20151211002707.147FEFB83@cvs.NetBSD.org

Log Message:
Update salt to 2015.8.3, provided by Travis Paul in PR 50507.

Security Fix

CVE-2015-8034: Saving state.sls cache data to disk with insecure permissions

This affects users of the state.sls function. The state run cache
on the minion was being created with incorrect permissions. This
file could potentially contain sensitive data that was inserted
via jinja into the state SLS files. The permissions for this file
are now being set correctly. Thanks to @zmalone for bringing this
issue to our attention.

Files:
RevisionActionfile
1.33modifypkgsrc/sysutils/salt/Makefile
1.14modifypkgsrc/sysutils/salt/PLIST
1.16modifypkgsrc/sysutils/salt/distinfo