Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Debian: DSA-2451-1 Critical: Puppet Remote Access Threats Overview

debian
Calendar Grey April 13, 2012
Scroller Debian
Improvements tackle multiple concerns in marionette enhancing safety and consistency; users encouraged to promptly refresh installations.
Several vulnerabilities have been discovered in puppet, a centralized configuration management system

Summary

Several vulnerabilities have been discovered in puppet, a centralized
configuration management system. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2012-1906

Puppet is using predictable temporary file names when downloading
Mac OS X package files. This allows a local attacker to either
overwrite arbitrary files on the system or to install an arbitrary
package.

CVE-2012-1986

When handling requests for a file from a remote filebucket, puppet
can be tricked into overwriting its defined location for filebucket
storage. This allows an authorized attacker with access to the puppet
master to read arbitrary files.

CVE-2012-1987

Puppet is incorrectly handling filebucket store requests. This allows
an attacker to perform denial of service attacks against puppet by
resource exhaustion.

CVE-2012-1988

Puppet is incorrectly handling filebucket requests. This allows an
attacker with access to the certificate on the ag...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: puppet

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.