Executive Summary

Informations
NameCVE-2010-0156First vendor Publication2010-03-03
VendorCveLast vendor Modification2010-06-23

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:N/I:P/A:P)
Cvss Base Score3.3Attack RangeLocal
Cvss Impact Score4.9Attack ComplexityMedium
Cvss Expoit Score3.4AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0156

CWE : Common Weakness Enumeration

idName
CWE-59Improper Link Resolution Before File Access ('Link Following')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application20

OpenVAS Exploits

DateDescription
2012-03-12Name : Gentoo Security Advisory GLSA 201203-03 (puppet)
File : nvt/glsa_201203_03.nasl
2010-03-31Name : Ubuntu Update for puppet vulnerabilities USN-917-1
File : nvt/gb_ubuntu_USN_917_1.nasl
2010-03-05Name : Fedora Update for puppet FEDORA-2010-1079
File : nvt/gb_fedora_2010_1079_puppet_fc11.nasl
2010-03-05Name : Fedora Update for puppet FEDORA-2010-1372
File : nvt/gb_fedora_2010_1372_puppet_fc12.nasl

Open Source Vulnerability Database (OSVDB)

idDescription
62752Puppet Multiple Temporary File Symlink Arbitrary File Overwrite

Nessus® Vulnerability Scanner

DateDescription
2012-03-06Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201203-03.nasl - Type : ACT_GATHER_INFO
2010-12-02Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_puppet-100310.nasl - Type : ACT_GATHER_INFO
2010-07-01Name : The remote Fedora host is missing a security update.
File : fedora_2010-1372.nasl - Type : ACT_GATHER_INFO
2010-07-01Name : The remote Fedora host is missing a security update.
File : fedora_2010-1079.nasl - Type : ACT_GATHER_INFO
2010-06-02Name : The remote SuSE system is missing a security patch for puppet
File : suse_11_1_puppet-100305.nasl - Type : ACT_GATHER_INFO
2010-06-02Name : The remote SuSE system is missing a security patch for puppet
File : suse_11_2_puppet-100305.nasl - Type : ACT_GATHER_INFO
2010-03-25Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-917-1.nasl - Type : ACT_GATHER_INFO

Internal Sources (Detail)

SourceUrl
CONFIRMhttps://bugzilla.redhat.com/show_bug.cgi?id=502881
FEDORAhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036083.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036166.html
MLISThttp://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6...
http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b289...
SECUNIAhttp://secunia.com/advisories/38766
SUSEhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html

Alert History

If you want to see full details history, please login or register.
0
1
DateInformations
2014-02-17 10:53:18
  • Multiple Updates
2013-05-10 23:16:27
  • Multiple Updates