DSA-2511-1 puppet -- several vulnerabilities

Related Vulnerabilities: CVE-2012-3864   CVE-2012-3865   CVE-2012-3866   CVE-2012-3867  

Several security vulnerabilities have been found in Puppet, a centralized configuration management: CVE-2012-3864 Authenticated clients could read arbitrary files on the puppet master. CVE-2012-3865 Authenticated clients could delete arbitrary files on the puppet master. CVE-2012-3866 The report of the most recent Puppet run was stored with world readable permissions, resulting in information disclosure. CVE-2012-3867 Agent hostnames were insufficiently validated. For the stable distribution (squeeze), this problem has been fixed in version 2.6.2-5+squeeze6. For the unstable distribution (sid), this problem has been fixed in version 2.7.18-1. We recommend that you upgrade your puppet packages.

Debian Security Advisory

DSA-2511-1 puppet -- several vulnerabilities

Date Reported:
12 Jul 2012
Affected Packages:
puppet
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867.
More information:

Several security vulnerabilities have been found in Puppet, a centralized configuration management:

  • CVE-2012-3864

    Authenticated clients could read arbitrary files on the puppet master.

  • CVE-2012-3865

    Authenticated clients could delete arbitrary files on the puppet master.

  • CVE-2012-3866

    The report of the most recent Puppet run was stored with world readable permissions, resulting in information disclosure.

  • CVE-2012-3867

    Agent hostnames were insufficiently validated.

For the stable distribution (squeeze), this problem has been fixed in version 2.6.2-5+squeeze6.

For the unstable distribution (sid), this problem has been fixed in version 2.7.18-1.

We recommend that you upgrade your puppet packages.