Lucene search

K
cve[email protected]CVE-2012-3867
HistoryAug 06, 2012 - 4:55 p.m.

CVE-2012-3867

2012-08-0616:55:06
CWE-264
web.nvd.nist.gov
65
cve-2012-3867
puppet
ssl
certificate authority
remote attack
ansi control sequences

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

82.2%

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

Affected configurations

NVD
Node
puppetpuppetMatch2.6.0
OR
puppetpuppetMatch2.6.1
OR
puppetpuppetMatch2.6.2
OR
puppetpuppetMatch2.6.3
OR
puppetpuppetMatch2.6.4
OR
puppetpuppetMatch2.6.5
OR
puppetpuppetMatch2.6.6
OR
puppetpuppetMatch2.6.7
OR
puppetpuppetMatch2.6.8
OR
puppetpuppetMatch2.6.9
OR
puppetpuppetMatch2.6.10
OR
puppetpuppetMatch2.6.11
OR
puppetpuppetMatch2.6.12
OR
puppetpuppetMatch2.6.13
OR
puppetpuppetMatch2.6.14
OR
puppetpuppetMatch2.6.15
OR
puppetpuppetMatch2.7.2
OR
puppetpuppetMatch2.7.3
OR
puppetpuppetMatch2.7.4
OR
puppetpuppetMatch2.7.5
OR
puppetpuppetMatch2.7.6
OR
puppetpuppetMatch2.7.7
OR
puppetpuppetMatch2.7.8
OR
puppetpuppetMatch2.7.9
OR
puppetpuppetMatch2.7.10
OR
puppetpuppetMatch2.7.11
OR
puppetpuppetMatch2.7.12
OR
puppetpuppetMatch2.7.13
OR
puppetpuppetMatch2.7.14
OR
puppetpuppetMatch2.7.16
OR
puppetpuppetMatch2.7.17
OR
puppetlabspuppetRange2.6.16
OR
puppetlabspuppetMatch2.7.0
OR
puppetlabspuppetMatch2.7.1
Node
debiandebian_linuxMatch6.0
Node
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch11.04
OR
canonicalubuntu_linuxMatch11.10
OR
canonicalubuntu_linuxMatch12.04lts
Node
opensuseopensuseMatch11.4
OR
opensuseopensuseMatch12.1
OR
suselinux_enterprise_desktopMatch11sp1
OR
suselinux_enterprise_desktopMatch11sp2
OR
suselinux_enterprise_serverMatch11sp1
OR
suselinux_enterprise_serverMatch11sp1vmware
OR
suselinux_enterprise_serverMatch11sp2
Node
puppetpuppet_enterpriseRange2.5.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

82.2%