2.1

CVE-2013-4969

Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version >= 3.0.0 <= 3.3.2
Puppetlabs ≫ Puppet Version >= 3.4.0 < 3.4.1
Puppet ≫ Puppet Enterprise Version >= 2.0.0 < 2.8.4
Puppet ≫ Puppet Enterprise Version >= 3.1 < 3.1.1
Debian ≫ Debian Linux Version 6.0
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Canonical ≫ Ubuntu Linux Version 13.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.341
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://puppetlabs.com/security/cve/cve-2013-4969
Vendor Advisory
http://secunia.com/advisories/56253
Vendor Advisory
http://secunia.com/advisories/56254
Vendor Advisory
http://www.debian.org/security/2013/dsa-2831
Third Party Advisory
http://www.ubuntu.com/usn/USN-2077-1
Third Party Advisory