Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.04 LTS USN-2077-2 Moderate: Puppet Regression Fix

ubuntu
Calendar Grey January 9, 2014
Scroller Ubuntu
Ubuntu Security Notice USN-2078-1 resolves an issue in OpenSSL impacting various Ubuntu distributions from February 2024.
USN-2077-1 introduced a regression in Puppet.

Summary

USN-2077-1 introduced a regression in Puppet.

Software Description:

- puppet: Centralized configuration management

Details:

USN-2077-1 fixed a vulnerability in Puppet. The upstream patch introduced a

regression resulting in the default file mode being incorrect. This update

fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Puppet incorrectly handled temporary files. A local

attacker could possibly use this issue to overwrite arbitrary files. In the

default installation of Ubuntu, this should be prevented by the Yama link

restrictions.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  puppet-common                   3.2.4-2ubuntu2.3

Ubuntu 13.04:
  puppet-common                   2.7.18-4ubuntu1.4

Ubuntu 12.10:
  puppet-common                   2.7.18-1ubuntu1.5

Ubuntu 12.04 LTS:
  puppet-common                   2.7.11-1ubuntu2.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2077-2

https://ubuntu.com/security/notices/USN-2077-1

https://bugs.launchpad.net/ubuntu/+source/puppet/+bug/1267385

January 09, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.