Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Ubuntu 11.10 Moderate: Puppet Security Advisory USN-1419-1 Local Attack

ubuntu
Calendar Grey April 11, 2012
Scroller Ubuntu
Various vulnerabilities addressed in Puppet for different Ubuntu versions, strengthening overall system protection.
Several security issues were fixed in puppet.

Summary

Several security issues were fixed in puppet.

Software Description:

- puppet: Centralized configuration management

Details:

It was discovered that Puppet used a predictable filename when downloading Mac

OS X package files. A local attacker could exploit this to overwrite arbitrary

files. (CVE-2012-1906)

It was discovered that Puppet incorrectly handled filebucket retrieval

requests. A local attacker could exploit this to read arbitrary files.

(CVE-2012-1986)

It was discovered that Puppet incorrectly handled filebucket store requests. A

local attacker could exploit this to perform a denial of service via resource

exhaustion. (CVE-2012-1987)

It was discovered that Puppet incorrectly handled filebucket requests. A local

attacker could exploit this to execute arbitrary code via a crafted file path.

(CVE-2012-1988)

It was discovered that Puppet used a predictable filename for the Telnet

connection log file. A local attacker could exploit this to overwrite arbitrary

files. This is...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  puppet-common                   2.7.1-1ubuntu3.6

Ubuntu 11.04:
  puppet-common                   2.6.4-2ubuntu2.9

Ubuntu 10.04 LTS:
  puppet-common                   0.25.4-2ubuntu6.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1419-1

CVE-2012-1906, CVE-2012-1986, CVE-2012-1987, CVE-2012-1988,

CVE-2012-1989

Severity
important
Lowest
Low
Medium
High
Critical

April 11, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.