Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1654
HistoryMar 12, 2013 - 12:00 a.m.

CVE-2013-1654

2013-03-1200:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.008

Percentile

81.4%

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise
2.7.x before 2.7.2, does not properly negotiate the SSL protocol between
client and master, which allows remote attackers to conduct SSLv2 downgrade
attacks against SSLv3 sessions via unspecified vectors.

Notes

Author Note
mdeslaur Upstream no longer supports 0.25.x as found in lucid. The code is substantially different, rendering a backport of this security update difficult. Since puppet in Lucid is almost end-of-life, we aren’t planning on backporting the security fix to it. For Lucid users, we recommend using puppet 2.7.1-1ubuntu3.8~ubuntu10.04.1 currently in lucid-backports.
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchpuppet< 2.7.1-1ubuntu3.8UNKNOWN
ubuntu12.04noarchpuppet< 2.7.11-1ubuntu2.2UNKNOWN
ubuntu12.10noarchpuppet< 2.7.18-1ubuntu1.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

EPSS

0.008

Percentile

81.4%