Debian Security Advisory
DSA-2511-1 puppet -- several vulnerabilities
- Date Reported:
- 12 Jul 2012
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867.
- More information:
Several security vulnerabilities have been found in Puppet, a centralized configuration management:
Authenticated clients could read arbitrary files on the puppet master.
Authenticated clients could delete arbitrary files on the puppet master.
The report of the most recent Puppet run was stored with world readable permissions, resulting in information disclosure.
Agent hostnames were insufficiently validated.
For the stable distribution (squeeze), this problem has been fixed in version 2.6.2-5+squeeze6.
For the unstable distribution (sid), this problem has been fixed in version 2.7.18-1.
We recommend that you upgrade your puppet packages.