Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for puppet fixes a remote code execution
vulnerability in the "resource_type" service.
(CVE-2013-4761)
Additionally, the update prevents puppet from executing
initialization scripts that could trigger a system reboot
when handling "puppet resource service" calls.
Security Issue reference:
* CVE-2013-4761
#835122 #853982
Cross- CVE-2013-4761
Affected Products:
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2013-4761.html
Get the latest Linux and open source security news straight to your inbox.