CVE Vulnerabilities

CVE-2012-1989

Published: Jun 27, 2012 | Modified: Jul 11, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

Affected Software

Name Vendor Start Version End Version
Puppet Puppet 2.7.3 (including) 2.7.3 (including)
Puppet Puppet 2.7.4 (including) 2.7.4 (including)
Puppet Puppet 2.7.5 (including) 2.7.5 (including)
Puppet Puppet 2.7.6 (including) 2.7.6 (including)
Puppet Puppet 2.7.8 (including) 2.7.8 (including)
Puppet Puppet 2.7.9 (including) 2.7.9 (including)
Puppet Puppet 2.7.10 (including) 2.7.10 (including)
Puppet Puppet 2.7.11 (including) 2.7.11 (including)
Puppet Puppet 2.7.12 (including) 2.7.12 (including)
Puppet Puppetlabs 2.7.0 (including) 2.7.0 (including)
Puppet Puppetlabs 2.7.1 (including) 2.7.1 (including)
Puppet Ubuntu devel *
Puppet Ubuntu hardy *
Puppet Ubuntu oneiric *

References