MEDIUM
GHSA-qh3g-27jf-3j54
Puppet allows local users to modify the permissions of arbitrary files
Quick fix
GHSA-qh3g-27jf-3j54 — puppet: upgrade to the fixed version with the command below.
bundle update puppetDetails
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2011-3870[ADVISORY]
- https://github.com/puppetlabs/puppet/commit/88512e880bd2a03694b5fef42540dc7b3da05d30[WEB]
- https://github.com/puppetlabs/puppet/commit/b29b1785d543a3cea961fffa9b3c15f14ab7cce0[WEB]
- https://github.com/puppetlabs/puppet[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puppet/CVE-2011-3870.yml[WEB]
- https://puppet.com/security/cve/cve-2011-3870[WEB]
- http://groups.google.com/group/puppet-announce/browse_thread/thread/91e3b46d2328a1cb[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068053.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068061.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2011-October/068093.html[WEB]
- http://www.debian.org/security/2011/dsa-2314[WEB]
- http://www.ubuntu.com/usn/USN-1223-1[WEB]
- http://www.ubuntu.com/usn/USN-1223-2[WEB]