Lucene search

K
ubuntuUbuntuUSN-917-1
HistoryMar 24, 2010 - 12:00 a.m.

Puppet vulnerabilities

2010-03-2400:00:00
ubuntu.com
35

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 9.10

Packages

  • puppet -

Details

It was discovered that Puppet did not drop supplementary groups when being
run as a different user. A local user may be able to use this flaw to
bypass security restrictions and gain access to restricted files.
(CVE-2009-3564)

It was discovered that Puppet did not correctly handle temporary files. A
local user can exploit this flaw to bypass security restrictions and
overwrite arbitrary files. (CVE-2010-0156)

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchpuppet< 0.24.8-2ubuntu4.1UNKNOWN
Ubuntu9.10noarchpuppet-testsuite< 0.24.8-2ubuntu4.1UNKNOWN
Ubuntu9.10noarchpuppetmaster< 0.24.8-2ubuntu4.1UNKNOWN

CVSS2

4.7

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:C/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0

Percentile

5.1%