Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in Puppet
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in Puppet
ID: USN-1217-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Do, 29. September 2011, 06:27
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3848
Applikationen: Puppet

Originalnachricht


--===============9009376196671490633==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-NOuxHUizZ7kD6Bb2isU2"


--=-NOuxHUizZ7kD6Bb2isU2
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1217-1
September 29, 2011

puppet vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

An attacker could send crafted input to puppet and cause it to overwrite
files.

Software Description:
- puppet: Centralized configuration management - agent startup and compatib

Details:

Kristian Erik Hermansen discovered a directory traversal vulnerability in
the SSLFile indirection base class. A remote attacker could exploit this to
overwrite files with the privileges of the Puppet Master.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
puppet-common 2.6.4-2ubuntu2.2

Ubuntu 10.10:
puppet-common 2.6.1-0ubuntu2.1

Ubuntu 10.04 LTS:
puppet-common 0.25.4-2ubuntu6.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1217-1
CVE-2011-3848

Package Information:
https://launchpad.net/ubuntu/+source/puppet/2.6.4-2ubuntu2.2
https://launchpad.net/ubuntu/+source/puppet/2.6.1-0ubuntu2.1
https://launchpad.net/ubuntu/+source/puppet/0.25.4-2ubuntu6.2



--×OuxHUizZ7kD6Bb2isU2
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOg9DhAAoJEFHb3FjMVZVzEdoP/Av6/iI18V7VoD0CGSIbBea2
t3Fq6/atFCnvNrOBQvfM8UFUIe2Rq0OuG95UORKa9VrEYs9vMEx2fc6tUOnlNZVM
rpitDPjDQyv7BCsE3ryDO+yNxq8ERDYKj6zMajnJOWMdKCvrPehfsF9xCZ8Thj10
BiPFOvfbT7m1vZ4MMj91RcBJ7O1//CMeDzyjPwtYxIDzkLHEBe7I4cr76Yg2a5NB
dC0lKXhSEsDpTiyDeSpG0dnHeozEGuhtuiKD+/4rMdxuR94P4EDbMkdlMG3hwyle
Fpr5uLFr7I385WxkCKz/G1FLO4RmQnMTytWYwH9ZdDrCy6ScnEiZ08jpArOAhBsb
KFF1wo08LvZJYiGGvisuY2HGPg7eL3G/NGLdy0ZdATxWPw0z1/uNDynlbPTeEGni
pJBOMN3ZKewz8WAvfZ57GnvEM9YoIyH+OnUWf3/g93JkzRZx/eIGrzRJjQgxKTRe
yhy//2E22fcRsTbo6uGAYpSI8ZxU35fkCCk8nlegx3JtXIBBzU2MhlB75HfdWQ1e
HWiiQ/2oH3BwIc4bNVaPz1cZFHJQvijMW3H8tQFizg/TYGCgjX7X5194hcU43G1U
sdFSA9yef9SngULaixh+sn1gR9uMccr++QdZ37CRYk9b6CfT34fipePDJ/xtFQJn
ywFA1YPpAkJKcFaGfPXK
=1x5y
-----END PGP SIGNATURE-----

--=-NOuxHUizZ7kD6Bb2isU2--



--===============9009376196671490633==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============9009376196671490633==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung