Lucene search

K
cveMitreCVE-2012-1989
HistoryJun 27, 2012 - 6:55 p.m.

CVE-2012-1989

2012-06-2718:55:01
CWE-264
mitre
web.nvd.nist.gov
68
cve-2012-1989
telnet.rb
puppet
puppet 2.7
puppet enterprise 1.2
puppet enterprise 2.0
puppet enterprise 2.5
symlink attack
nvd

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%

telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).

Affected configurations

Nvd
Node
puppetpuppetMatch2.7.3
OR
puppetpuppetMatch2.7.4
OR
puppetpuppetMatch2.7.5
OR
puppetpuppetMatch2.7.6
OR
puppetpuppetMatch2.7.8
OR
puppetpuppetMatch2.7.9
OR
puppetpuppetMatch2.7.10
OR
puppetpuppetMatch2.7.11
OR
puppetpuppetMatch2.7.12
OR
puppetlabspuppetMatch2.7.0
OR
puppetlabspuppetMatch2.7.1
Node
puppetpuppet_enterpriseMatch1.2.0
OR
puppetpuppet_enterpriseMatch1.2.1
OR
puppetpuppet_enterpriseMatch1.2.2
OR
puppetpuppet_enterpriseMatch1.2.3
OR
puppetpuppet_enterpriseMatch1.2.4
OR
puppetpuppet_enterpriseMatch2.0.0
OR
puppetpuppet_enterpriseMatch2.0.1
OR
puppetpuppet_enterpriseMatch2.0.2
OR
puppetpuppet_enterpriseMatch2.5.0
VendorProductVersionCPE
puppetpuppet2.7.3cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:*
puppetpuppet2.7.4cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:*
puppetpuppet2.7.5cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:*
puppetpuppet2.7.6cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:*
puppetpuppet2.7.8cpe:2.3:a:puppet:puppet:2.7.8:*:*:*:*:*:*:*
puppetpuppet2.7.9cpe:2.3:a:puppet:puppet:2.7.9:*:*:*:*:*:*:*
puppetpuppet2.7.10cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:*
puppetpuppet2.7.11cpe:2.3:a:puppet:puppet:2.7.11:*:*:*:*:*:*:*
puppetpuppet2.7.12cpe:2.3:a:puppet:puppet:2.7.12:*:*:*:*:*:*:*
puppetlabspuppet2.7.0cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%