6

CVE-2012-1988

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppet ≫ Puppet Version >= 2.6.0 < 2.6.15
Puppet ≫ Puppet Version >= 2.7.0 < 2.7.13
Puppet ≫ Puppet Enterprise Version >= 1.2.0 < 2.5.1
Puppet ≫ Puppet Enterprise Version 1.0
Puppet ≫ Puppet Enterprise Version 1.1
Fedoraproject ≫ Fedora Version 15
Fedoraproject ≫ Fedora Version 16
Fedoraproject ≫ Fedora Version 17
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Canonical ≫ Ubuntu Linux Version 10.04
Canonical ≫ Ubuntu Linux Version 11.04
Canonical ≫ Ubuntu Linux Version 11.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.63% 0.836
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://hermes.opensuse.org/messages/15087408
Broken Link
http://secunia.com/advisories/48743
Vendor Advisory
Broken Link
http://secunia.com/advisories/48748
Vendor Advisory
Broken Link
http://secunia.com/advisories/48789
Vendor Advisory
Broken Link
http://ubuntu.com/usn/usn-1419-1
Third Party Advisory
http://www.debian.org/security/2012/dsa-2451
Third Party Advisory
http://www.securityfocus.com/bid/52975
Third Party Advisory
Broken Link
VDB Entry
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.html
Third Party Advisory
Mailing List
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.html
Third Party Advisory
Mailing List
http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15
Broken Link
http://secunia.com/advisories/49136
Vendor Advisory
Broken Link
https://hermes.opensuse.org/messages/14523305
Broken Link
http://projects.puppetlabs.com/issues/13518
Vendor Advisory
Broken Link
http://puppetlabs.com/security/cve/cve-2012-1988/
Vendor Advisory
Broken Link
http://www.osvdb.org/81309
Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/74796
Third Party Advisory
VDB Entry