Lucene search

K
debianDebianDEBIAN:BSA-055:FE09A
HistoryNov 01, 2011 - 2:36 p.m.

[BSA-055] Security update for puppet

2011-11-0114:36:03
lists.debian.org
20

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

74.2%

Micah Anderson uploaded new packages for puppet which fixed the
following security problems:

CVE-2011-3872
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet
Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an
agent certificate, adds the Puppet master's certdnsnames values to the
X.509 Subject Alternative Name field of the certificate, which allows
remote attackers to spoof a Puppet master via a man-in-the-middle
(MITM) attack against an agent that uses an alternate DNS name for the
master, aka "AltNames Vulnerability."

For the squeeze-backports distribution the problems have been fixed in
version 2.7.6-1~bpo60+1.

Attachment:
pgp546M1CdwI9.pgp
Description: PGP signature

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

74.2%