puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Puppet | Reductivelabs | 0.24.6 (including) | 0.24.6 (including) |
Puppet | Ubuntu | hardy | * |
Puppet | Ubuntu | intrepid | * |
Puppet | Ubuntu | jaunty | * |
Puppet | Ubuntu | karmic | * |