Monday, January 6, 2014

USN-2077-1: Puppet vulnerability

Ubuntu Security Notice USN-2077-1


6th January, 2014


puppet vulnerability


A security issue affects these releases of Ubuntu and its derivatives:



  • Ubuntu 13.10

  • Ubuntu 13.04

  • Ubuntu 12.10

  • Ubuntu 12.04 LTS


Summary


Puppet could be made to overwrite files.


Software description



  • puppet - Centralized configuration management


Details


It was discovered that Puppet incorrectly handled temporary files. A local

attacker could possibly use this issue to overwrite arbitrary files. In the

default installation of Ubuntu, this should be prevented by the Yama link

restrictions.


Update instructions


The problem can be corrected by updating your system to the following package version:



Ubuntu 13.10:

puppet-common 3.2.4-2ubuntu2.2

Ubuntu 13.04:

puppet-common 2.7.18-4ubuntu1.3

Ubuntu 12.10:

puppet-common 2.7.18-1ubuntu1.4

Ubuntu 12.04 LTS:

puppet-common 2.7.11-1ubuntu2.6


To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.


In general, a standard system update will make all the necessary changes.


References


CVE-2013-4969






via Ubuntu Security Notices http://www.ubuntu.com/usn/usn-2077-1/

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.