CVE Vulnerabilities

CVE-2012-1054

Published: May 29, 2012 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.

Affected Software

Name Vendor Start Version End Version
Puppet Puppet 2.6.0 (including) 2.6.0 (including)
Puppet Puppet 2.6.1 (including) 2.6.1 (including)
Puppet Puppet 2.6.2 (including) 2.6.2 (including)
Puppet Puppet 2.6.3 (including) 2.6.3 (including)
Puppet Puppet 2.6.4 (including) 2.6.4 (including)
Puppet Puppet 2.6.5 (including) 2.6.5 (including)
Puppet Puppet 2.6.6 (including) 2.6.6 (including)
Puppet Puppet 2.6.7 (including) 2.6.7 (including)
Puppet Puppet 2.6.8 (including) 2.6.8 (including)
Puppet Puppet 2.6.9 (including) 2.6.9 (including)
Puppet Puppet 2.6.10 (including) 2.6.10 (including)
Puppet Puppet 2.6.11 (including) 2.6.11 (including)
Puppet Puppet 2.6.12 (including) 2.6.12 (including)
Puppet Puppet 2.6.13 (including) 2.6.13 (including)
Puppet Ubuntu hardy *
Puppet Ubuntu lucid *
Puppet Ubuntu maverick *
Puppet Ubuntu natty *
Puppet Ubuntu oneiric *
Puppet Ubuntu upstream *

References