Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2012:0983-1 Critical: Puppet Service Denial Issue

suse
Calendar Grey August 13, 2012
Scroller Suse
Essential SUSE Security Upgrade for puppet addressing three significant vulnerabilities. Ensure your systems remain protected with the newest updates and solutions.
An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now available

Summary

The following bugs have been fixed in puppet: * bnc#770828, CVE-2012-3864: puppet: authenticated clients can read arbitrary files via a flaw in puppet master * bnc#770829, CVE-2012-3865: puppet: arbitrary file delete / Denial of Service on Puppet Master by authenticated clients * bnc#770833, CVE-2012-3867: puppet: insufficient input validation for agent certificate names Security Issue references: * CVE-2012-3867 * CVE-2012-3864 * CVE-2012-3865 Patch Instructions: To install this SUSE Security Update use YaST online_update.

References

#770828 #770829 #770833

Cross- CVE-2012-3864 CVE-2012-3865 CVE-2012-3867

Affected Products:

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Server 11 SP1 for VMware

SUSE Linux Enterprise Server 11 SP1

SUSE Linux Enterprise Desktop 11 SP2

SUSE Linux Enterprise Desktop 11 SP1

https://www.suse.com/security/cve/CVE-2012-3864.html

https://www.suse.com/security/cve/CVE-2012-3865.html

https://www.suse.com/security/cve/CVE-2012-3867.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0983-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.