3.3
CVSSv2

CVE-2010-0156

Published: 03/03/2010 Updated: 09/12/2017
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Puppet 0.24.x prior to 0.24.9 and 0.25.x prior to 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet 0.24.6

puppet puppet 0.25.0

puppet puppet 0.25.1

puppet puppet 0.24.5

puppet puppet 0.25.2

puppet puppet 0.24.7

puppet puppet 0.24.8

puppet puppet 0.24.4

puppet puppet 0.24.3

Vendor Advisories

It was discovered that Puppet did not drop supplementary groups when being run as a different user A local user may be able to use this flaw to bypass security restrictions and gain access to restricted files (CVE-2009-3564) ...