Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Ubuntu 9.10 USN-917-1 Critical: Puppet Access Control Exploits

Ubuntu Large Esm H500
It was discovered that Puppet did not drop supplementary groups when being run as a different user. A local user may be able to use this flaw to bypass security restrictions and gain access to restricted files. (CVE-2009-3564) [More...]
==========================================================Ubuntu Security Notice USN-917-1             March 24, 2010
puppet vulnerabilities
CVE-2009-3564, CVE-2010-0156
==========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 9.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.10:
  puppet                          0.24.8-2ubuntu4.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

It was discovered that Puppet did not drop supplementary groups when being
run as a different user. A local user may be able to use this flaw to
bypass security restrictions and gain access to restricted files.
(CVE-2009-3564)

It was discovered that Puppet did not correctly handle temporary files. A
local user can exploit this flaw to bypass security restrictions and
overwrite arbitrary files. (CVE-2010-0156)


Updated packages for Ubuntu 9.10:

  Source archives:

          Size/MD5:    16108 228231bb7fafde0cd8555618017939ce
          Size/MD5:     1517 22118d6cf21742ca62796a0957bee5f8
          Size/MD5:  1093533 db02f46288794225d54b36f89e2725a7

  Architecture independent packages:

          Size/MD5:   518402 b050c03fffa3df3dc31faa12b17f6aa2
          Size/MD5:    47806 5fb4e692c93a7388d34f6a284f4a5e92
          Size/MD5:   418926 5785eb3a1e0d6373f0d891f72afca170



Ubuntu 9.10 USN-917-1 Critical: Puppet Access Control Exploits

ubuntu
Calendar Grey March 24, 2010
Dist Ubuntu Esm H88
Ubuntu Security Bulletin USN-917-1 outlines vulnerabilities in puppet that may permit unauthorized entry and file overwrite issues for users.
It was discovered that Puppet did not drop supplementary groups when being run as a different user

Summary

Update Instructions

References

Severity
critical
Lowest
Low
Medium
High
Critical

puppet vulnerabilities

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here