This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Puppetlabs First view 2011-10-27
Product Puppet Enterprise Users Last view 2012-05-29
Version 1.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:puppetlabs:puppet_enterprise_users

Activity : Overall

Related : CVE

  Date Alert Description
3.5 2012-05-29 CVE-2012-1987

Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.

2.1 2012-05-29 CVE-2012-1986

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.

3.3 2012-05-29 CVE-2012-1906

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.

4.4 2012-05-29 CVE-2012-1054

Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.

6.9 2012-05-29 CVE-2012-1053

The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.

2.6 2011-10-27 CVE-2011-3872

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

CWE : Common Weakness Enumeration

%idName
80% (4) CWE-264 Permissions, Privileges, and Access Controls
20% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
76623 Puppet certdnsnames Puppet Master Impersonation Weakness

OpenVAS Exploits

id Description
2012-08-30 Name : Gentoo Security Advisory GLSA 201208-02 (Puppet)
File : nvt/glsa_201208_02.nasl
2012-08-30 Name : Fedora Update for puppet FEDORA-2012-2325
File : nvt/gb_fedora_2012_2325_puppet_fc17.nasl
2012-08-30 Name : Fedora Update for puppet FEDORA-2012-6674
File : nvt/gb_fedora_2012_6674_puppet_fc17.nasl
2012-07-30 Name : Fedora Update for puppet FEDORA-2012-10897
File : nvt/gb_fedora_2012_10897_puppet_fc16.nasl
2012-04-30 Name : Debian Security Advisory DSA 2451-1 (puppet)
File : nvt/deb_2451_1.nasl
2012-04-30 Name : Debian Security Advisory DSA 2453-1 (gajim)
File : nvt/deb_2453_1.nasl
2012-04-30 Name : FreeBSD Ports: puppet
File : nvt/freebsd_puppet.nasl
2012-04-30 Name : Fedora Update for puppet FEDORA-2012-5999
File : nvt/gb_fedora_2012_5999_puppet_fc16.nasl
2012-04-30 Name : Fedora Update for puppet FEDORA-2012-6055
File : nvt/gb_fedora_2012_6055_puppet_fc15.nasl
2012-04-13 Name : Ubuntu Update for puppet USN-1419-1
File : nvt/gb_ubuntu_USN_1419_1.nasl
2012-04-02 Name : Fedora Update for puppet FEDORA-2012-2415
File : nvt/gb_fedora_2012_2415_puppet_fc16.nasl
2012-03-19 Name : Fedora Update for puppet FEDORA-2011-14880
File : nvt/gb_fedora_2011_14880_puppet_fc16.nasl
2012-03-12 Name : Fedora Update for puppet FEDORA-2012-2367
File : nvt/gb_fedora_2012_2367_puppet_fc15.nasl
2012-03-12 Name : Gentoo Security Advisory GLSA 201203-03 (puppet)
File : nvt/glsa_201203_03.nasl
2012-03-12 Name : Debian Security Advisory DSA 2419-1 (puppet)
File : nvt/deb_2419_1.nasl
2012-03-09 Name : Ubuntu Update for puppet USN-1372-1
File : nvt/gb_ubuntu_USN_1372_1.nasl
2012-02-11 Name : Debian Security Advisory DSA 2352-1 (puppet)
File : nvt/deb_2352_1.nasl
2011-11-21 Name : Fedora Update for puppet FEDORA-2011-15000
File : nvt/gb_fedora_2011_15000_puppet_fc14.nasl
2011-11-21 Name : Fedora Update for puppet FEDORA-2011-14994
File : nvt/gb_fedora_2011_14994_puppet_fc15.nasl
2011-10-31 Name : Ubuntu Update for puppet USN-1238-1
File : nvt/gb_ubuntu_USN_1238_1.nasl
2011-10-31 Name : Ubuntu Update for puppet USN-1238-2
File : nvt/gb_ubuntu_USN_1238_2.nasl

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_puppet-111110.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_puppet-111110.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-369.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2012-269.nasl - Type: ACT_GATHER_INFO
2013-09-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2012-75.nasl - Type: ACT_GATHER_INFO
2013-09-04 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2012-53.nasl - Type: ACT_GATHER_INFO
2013-01-25 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_puppet-120411.nasl - Type: ACT_GATHER_INFO
2012-08-15 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201208-02.nasl - Type: ACT_GATHER_INFO
2012-05-07 Name: The remote Fedora host is missing a security update.
File: fedora_2012-6674.nasl - Type: ACT_GATHER_INFO
2012-04-30 Name: The remote Fedora host is missing a security update.
File: fedora_2012-5999.nasl - Type: ACT_GATHER_INFO
2012-04-30 Name: The remote Fedora host is missing a security update.
File: fedora_2012-6055.nasl - Type: ACT_GATHER_INFO
2012-04-17 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2453.nasl - Type: ACT_GATHER_INFO
2012-04-16 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2451.nasl - Type: ACT_GATHER_INFO
2012-04-11 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-1419-1.nasl - Type: ACT_GATHER_INFO
2012-04-11 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_607d2108a0e4423abf78846f2a8f01b0.nasl - Type: ACT_GATHER_INFO
2012-03-12 Name: The remote Fedora host is missing a security update.
File: fedora_2012-2325.nasl - Type: ACT_GATHER_INFO
2012-03-12 Name: The remote Fedora host is missing a security update.
File: fedora_2012-2367.nasl - Type: ACT_GATHER_INFO
2012-03-12 Name: The remote Fedora host is missing a security update.
File: fedora_2012-2415.nasl - Type: ACT_GATHER_INFO
2012-03-06 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201203-03.nasl - Type: ACT_GATHER_INFO
2012-03-05 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_puppet-120224.nasl - Type: ACT_GATHER_INFO
2012-02-28 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2419.nasl - Type: ACT_GATHER_INFO
2012-02-24 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-1372-1.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_puppet-111111.nasl - Type: ACT_GATHER_INFO
2011-11-23 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2352.nasl - Type: ACT_GATHER_INFO
2011-11-22 Name: The remote Fedora host is missing a security update.
File: fedora_2011-15000.nasl - Type: ACT_GATHER_INFO