Summary
Detail | |||
---|---|---|---|
Vendor | Puppetlabs | First view | 2011-10-27 |
Product | Puppet Enterprise Users | Last view | 2012-05-29 |
Version | 1.0 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:puppetlabs:puppet_enterprise_users |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
3.5 | 2012-05-29 | CVE-2012-1987 | Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations. |
2.1 | 2012-05-29 | CVE-2012-1986 | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket. |
3.3 | 2012-05-29 | CVE-2012-1906 | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp. |
4.4 | 2012-05-29 | CVE-2012-1054 | Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login. |
6.9 | 2012-05-29 | CVE-2012-1053 | The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups. |
2.6 | 2011-10-27 | CVE-2011-3872 | Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability." |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
80% (4) | CWE-264 | Permissions, Privileges, and Access Controls |
20% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
76623 | Puppet certdnsnames Puppet Master Impersonation Weakness |
OpenVAS Exploits
id | Description |
---|---|
2012-08-30 | Name : Gentoo Security Advisory GLSA 201208-02 (Puppet) File : nvt/glsa_201208_02.nasl |
2012-08-30 | Name : Fedora Update for puppet FEDORA-2012-2325 File : nvt/gb_fedora_2012_2325_puppet_fc17.nasl |
2012-08-30 | Name : Fedora Update for puppet FEDORA-2012-6674 File : nvt/gb_fedora_2012_6674_puppet_fc17.nasl |
2012-07-30 | Name : Fedora Update for puppet FEDORA-2012-10897 File : nvt/gb_fedora_2012_10897_puppet_fc16.nasl |
2012-04-30 | Name : Debian Security Advisory DSA 2451-1 (puppet) File : nvt/deb_2451_1.nasl |
2012-04-30 | Name : Debian Security Advisory DSA 2453-1 (gajim) File : nvt/deb_2453_1.nasl |
2012-04-30 | Name : FreeBSD Ports: puppet File : nvt/freebsd_puppet.nasl |
2012-04-30 | Name : Fedora Update for puppet FEDORA-2012-5999 File : nvt/gb_fedora_2012_5999_puppet_fc16.nasl |
2012-04-30 | Name : Fedora Update for puppet FEDORA-2012-6055 File : nvt/gb_fedora_2012_6055_puppet_fc15.nasl |
2012-04-13 | Name : Ubuntu Update for puppet USN-1419-1 File : nvt/gb_ubuntu_USN_1419_1.nasl |
2012-04-02 | Name : Fedora Update for puppet FEDORA-2012-2415 File : nvt/gb_fedora_2012_2415_puppet_fc16.nasl |
2012-03-19 | Name : Fedora Update for puppet FEDORA-2011-14880 File : nvt/gb_fedora_2011_14880_puppet_fc16.nasl |
2012-03-12 | Name : Fedora Update for puppet FEDORA-2012-2367 File : nvt/gb_fedora_2012_2367_puppet_fc15.nasl |
2012-03-12 | Name : Gentoo Security Advisory GLSA 201203-03 (puppet) File : nvt/glsa_201203_03.nasl |
2012-03-12 | Name : Debian Security Advisory DSA 2419-1 (puppet) File : nvt/deb_2419_1.nasl |
2012-03-09 | Name : Ubuntu Update for puppet USN-1372-1 File : nvt/gb_ubuntu_USN_1372_1.nasl |
2012-02-11 | Name : Debian Security Advisory DSA 2352-1 (puppet) File : nvt/deb_2352_1.nasl |
2011-11-21 | Name : Fedora Update for puppet FEDORA-2011-15000 File : nvt/gb_fedora_2011_15000_puppet_fc14.nasl |
2011-11-21 | Name : Fedora Update for puppet FEDORA-2011-14994 File : nvt/gb_fedora_2011_14994_puppet_fc15.nasl |
2011-10-31 | Name : Ubuntu Update for puppet USN-1238-1 File : nvt/gb_ubuntu_USN_1238_1.nasl |
2011-10-31 | Name : Ubuntu Update for puppet USN-1238-2 File : nvt/gb_ubuntu_USN_1238_2.nasl |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: suse_11_4_puppet-111110.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: suse_11_3_puppet-111110.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2012-369.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2012-269.nasl - Type: ACT_GATHER_INFO |
2013-09-04 | Name: The remote Amazon Linux AMI host is missing a security update. File: ala_ALAS-2012-75.nasl - Type: ACT_GATHER_INFO |
2013-09-04 | Name: The remote Amazon Linux AMI host is missing a security update. File: ala_ALAS-2012-53.nasl - Type: ACT_GATHER_INFO |
2013-01-25 | Name: The remote SuSE 11 host is missing one or more security updates. File: suse_11_puppet-120411.nasl - Type: ACT_GATHER_INFO |
2012-08-15 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201208-02.nasl - Type: ACT_GATHER_INFO |
2012-05-07 | Name: The remote Fedora host is missing a security update. File: fedora_2012-6674.nasl - Type: ACT_GATHER_INFO |
2012-04-30 | Name: The remote Fedora host is missing a security update. File: fedora_2012-5999.nasl - Type: ACT_GATHER_INFO |
2012-04-30 | Name: The remote Fedora host is missing a security update. File: fedora_2012-6055.nasl - Type: ACT_GATHER_INFO |
2012-04-17 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-2453.nasl - Type: ACT_GATHER_INFO |
2012-04-16 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-2451.nasl - Type: ACT_GATHER_INFO |
2012-04-11 | Name: The remote Ubuntu host is missing a security-related patch. File: ubuntu_USN-1419-1.nasl - Type: ACT_GATHER_INFO |
2012-04-11 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_607d2108a0e4423abf78846f2a8f01b0.nasl - Type: ACT_GATHER_INFO |
2012-03-12 | Name: The remote Fedora host is missing a security update. File: fedora_2012-2325.nasl - Type: ACT_GATHER_INFO |
2012-03-12 | Name: The remote Fedora host is missing a security update. File: fedora_2012-2367.nasl - Type: ACT_GATHER_INFO |
2012-03-12 | Name: The remote Fedora host is missing a security update. File: fedora_2012-2415.nasl - Type: ACT_GATHER_INFO |
2012-03-06 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201203-03.nasl - Type: ACT_GATHER_INFO |
2012-03-05 | Name: The remote SuSE 11 host is missing one or more security updates. File: suse_11_puppet-120224.nasl - Type: ACT_GATHER_INFO |
2012-02-28 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-2419.nasl - Type: ACT_GATHER_INFO |
2012-02-24 | Name: The remote Ubuntu host is missing a security-related patch. File: ubuntu_USN-1372-1.nasl - Type: ACT_GATHER_INFO |
2011-12-13 | Name: The remote SuSE 11 host is missing one or more security updates. File: suse_11_puppet-111111.nasl - Type: ACT_GATHER_INFO |
2011-11-23 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-2352.nasl - Type: ACT_GATHER_INFO |
2011-11-22 | Name: The remote Fedora host is missing a security update. File: fedora_2011-15000.nasl - Type: ACT_GATHER_INFO |