Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The deployment framework puppet received an update for a
security issue in January.
The backport of this security issue was however incomplete
and broke existing setups. As the scope of the problem is
limited to local scenarios where an attacker likely has
access already, and backporting is not trivial, this
update reverts the fix for now.
We are evaluating the possibility of an update to puppet
2.7 in the future.
Security Issue reference:
* CVE-2013-4761
#864082
Cross- CVE-2013-4761
Affected Products:
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 LTSS
SUSE Linux Enterprise Desktop 11 SP3
https://www.suse.com/security/cve/CVE-2013-4761.html
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/
Get the latest Linux and open source security news straight to your inbox.