Permissions, Privileges, and Access Controls in Puppet Agent and Puppet Enterprise - CVE-2012-1989
Published: June 27, 2012 / Updated: August 11, 2020
Puppet Agent
Puppet Enterprise
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
How to mitigate CVE-2012-1989
Sources
- http://lists.opensuse.org/opensuse-updates/2012-05/msg00012.html
- http://projects.puppetlabs.com/issues/13606
- http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.7.13
- http://puppetlabs.com/security/cve/cve-2012-1989/
- http://secunia.com/advisories/48743
- http://secunia.com/advisories/48748
- http://secunia.com/advisories/49136
- http://ubuntu.com/usn/usn-1419-1
- http://www.securityfocus.com/bid/52975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74797
- https://hermes.opensuse.org/messages/15087408