runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ssh session via a symlink attack on a socket file with a predictable name in /tmp/.
{
"binaries": [
{
"binary_name": "ansible",
"binary_version": "1.5.4+dfsg-1"
},
{
"binary_name": "ansible-doc",
"binary_version": "1.5.4+dfsg-1"
},
{
"binary_name": "ansible-fireball",
"binary_version": "1.5.4+dfsg-1"
},
{
"binary_name": "ansible-node-fireball",
"binary_version": "1.5.4+dfsg-1"
}
],
"availability": "No subscription required"
}