CVE Vulnerabilities

CVE-2012-1989

Published: Jun 27, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

Affected Software

NameVendorStart VersionEnd Version
PuppetPuppet2.7.3 (including)2.7.3 (including)
PuppetPuppet2.7.4 (including)2.7.4 (including)
PuppetPuppet2.7.5 (including)2.7.5 (including)
PuppetPuppet2.7.6 (including)2.7.6 (including)
PuppetPuppet2.7.8 (including)2.7.8 (including)
PuppetPuppet2.7.9 (including)2.7.9 (including)
PuppetPuppet2.7.10 (including)2.7.10 (including)
PuppetPuppet2.7.11 (including)2.7.11 (including)
PuppetPuppet2.7.12 (including)2.7.12 (including)
PuppetPuppetlabs2.7.0 (including)2.7.0 (including)
PuppetPuppetlabs2.7.1 (including)2.7.1 (including)
PuppetUbuntudevel*
PuppetUbuntuhardy*
PuppetUbuntuoneiric*

References