3.6
CVSSv2

CVE-2012-1989

Published: 27/06/2012 Updated: 11/07/2019
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

telnet.rb in Puppet 2.7.x prior to 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x prior to 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet 2.7.8

puppet puppet 2.7.6

puppet puppet 2.7.11

puppet puppet 2.7.9

puppetlabs puppet 2.7.0

puppet puppet 2.7.12

puppet puppet 2.7.4

puppet puppet 2.7.3

puppetlabs puppet 2.7.1

puppet puppet 2.7.10

puppet puppet 2.7.5

puppet puppet enterprise 1.2.1

puppet puppet enterprise 1.2.4

puppet puppet enterprise 2.0.1

puppet puppet enterprise 2.5.0

puppet puppet enterprise 2.0.0

puppet puppet enterprise 2.0.2

puppet puppet enterprise 1.2.2

puppet puppet enterprise 1.2.0

puppet puppet enterprise 1.2.3

Vendor Advisories

Several security issues were fixed in puppet ...