[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2511-1 puppet -- several

ID: oval:org.secpod.oval:def:600847Date: (C)2012-07-18   (M)2022-10-10
Class: PATCHFamily: unix




Several security vulnerabilities have been found in Puppet, a centralized configuration management: CVE-2012-3864 Authenticated clients could read arbitrary files on the puppet master. CVE-2012-3865 Authenticated clients could delete arbitrary files on the puppet master. CVE-2012-3866 The report of the most recent Puppet run was stored with world- readable permissions, resulting in information disclosure. CVE-2012-3867 Agent hostnames were insufficiently validated.

Platform:
Debian 6.0
Product:
puppet
Reference:
DSA-2511-1
CVE-2012-3864
CVE-2012-3865
CVE-2012-3866
CVE-2012-3867
CVE    4
CVE-2012-3865
CVE-2012-3864
CVE-2012-3867
CVE-2012-3866
...
CPE    37
cpe:/a:puppetlabs:puppet:2.6.10
cpe:/o:debian:debian_linux:6.0
cpe:/a:puppetlabs:puppet:2.7.14
cpe:/a:puppetlabs:puppet:2.7.12
...

© SecPod Technologies