Puppet: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201203-03 / puppet |
| Release Date |
March 06, 2012 |
| Latest Revision |
March 06, 2012: 1 |
| Impact |
high |
| Exploitable |
local, remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-admin/puppet |
<
2.7.11 |
>=
2.7.11 |
All supported architectures
|
Related bugreports:
#303729, #308031, #384859, #385149, #388161, #403963
Synopsis
Multiple vulnerabilities have been found in Puppet, the worst of
which might allow local attackers to gain escalated privileges.
2.
Impact Information
Background
Puppet is a system configuration management tool written in Ruby.
Description
Multiple vulnerabilities have been discovered in Puppet. Please review
the CVE identifiers referenced below for details.
Impact
A local attacker could gain elevated privileges, or access and modify
arbitrary files. Furthermore, a remote attacker may be able to spoof a
Puppet Master or write X.509 Certificate Signing Requests to arbitrary
locations.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Puppet users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-admin/puppet-2.7.11"
|
4.
References
|