Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1506-1 Moderate Puppet Issues Detected

ubuntu
Calendar Grey July 12, 2012
Scroller Ubuntu
A number of vulnerabilities in Puppet have been mitigated through recent patches for Ubuntu, reinforcing system reliability and security.
Several security issues were fixed in Puppet.

Summary

Several security issues were fixed in Puppet.

Software Description:

- puppet: Centralized configuration management

Details:

It was discovered that Puppet incorrectly handled certain HTTP GET

requests. An attacker could use this flaw with a valid client certificate

to retrieve arbitrary files from the Puppet master. (CVE-2012-3864)

It was discovered that Puppet incorrectly handled Delete requests. If a

Puppet master were reconfigured to allow the "Delete" method, an attacker

on an authenticated host could use this flaw to delete arbitrary files from

the Puppet server, leading to a denial of service. (CVE-2012-3865)

It was discovered that Puppet incorrectly set file permissions on the

last_run_report.yaml file. An attacker could use this flaw to access

sensitive information. This issue only affected Ubuntu 11.10 and Ubuntu

12.04 LTS. (CVE-2012-3866)

It was discovered that Puppet incorrectly handled agent certificate names.

An attacker could use this flaw ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  puppet-common                   2.7.11-1ubuntu2.1

Ubuntu 11.10:
  puppet-common                   2.7.1-1ubuntu3.7

Ubuntu 11.04:
  puppet-common                   2.6.4-2ubuntu2.10

Ubuntu 10.04 LTS:
  puppet-common                   0.25.4-2ubuntu6.8

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1506-1

CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867

July 12, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.