Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: 3142-2 Moderate: Ansible Security Vulnerabilities Resolution Notice

debian
Calendar Grey September 19, 2013
Debian Logo
Debian has released an update for Puppet that resolves several security issues. To maintain the integrity of your system, make sure to install the latest updates promptly.
Several vulnerabilities were discovered in puppet, a centralized configuration management system

Summary

Several vulnerabilities were discovered in puppet, a centralized
configuration management system. The Common Vulnerabilities and
Exposures project identifies the following problems:

CVE-2013-4761

The 'resource_type' service (disabled by default) could be used to
make puppet load arbitrary Ruby code from puppet master's file
system.

CVE-2013-4956

Modules installed with the Puppet Module Tool might be installed
with weak permissions, possibly allowing local users to read or
modify them.

The stable distribution (wheezy) has been updated to version 2.7.33 of
puppet. This version includes the patches for all the previous DSAs
related to puppet in wheezy. In this version, the puppet report format
is now correctly reported as version 3.

It is to be expected that future DSAs for puppet update to a newer,
bug fix-only, release of the 2.7 branch.

The oldstable distribution (squeeze) has not been updated for this
advisory: as of this time there is no fix for CVE-2013-4761 and the
package ...

Read the Full Advisory

Package: puppet
CVE ID: CVE-2013-4761 CVE-2013-4956

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here