drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Prüfung von Zertifikaten in Puppet (Aktualisierung)
Name: |
Mangelnde Prüfung von Zertifikaten in Puppet (Aktualisierung) |
|
ID: |
USN-1238-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 11.04 |
|
Datum: |
Mi, 26. Oktober 2011, 14:33 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
Puppet |
|
Update von: |
Mangelnde Prüfung von Zertifikaten in Puppet |
|
Originalnachricht |
--===============4472500133395995111== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-0AjihcceJqi5q/XUFhgR"
--=-0AjihcceJqi5q/XUFhgR Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1238-2 October 25, 2011
puppet regression ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 11.04
Summary:
USN-1238-1 caused a regression on Ubuntu 11.04.
Software Description: - puppet: Centralized configuration management
Details:
USN-1238-1 fixed vulnerabilities in Puppet. The upstream patch introduced a regression in Ubuntu 11.04 when executing certain commands. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Puppet incorrectly handled the non-default "certdnsnames" option when generating certificates. If this setting was added to puppet.conf, the puppet masterâs DNS alt names were added to the X.509 Subject Alternative Name field of all certificates, not just the puppet masterâs certificate. An attacker that has an incorrect agent certificate in his possession can use it to impersonate the puppet master in a man-in-the-middle attack.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.04: puppet-common 2.6.4-2ubuntu2.6
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1238-2 http://www.ubuntu.com/usn/usn-1238-1 https://launchpad.net/bugs/881361
Package Information: https://launchpad.net/ubuntu/+source/puppet/2.6.4-2ubuntu2.6
--ÐAjihcceJqi5q/XUFhgR Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJOpwnNAAoJEGVp2FWnRL6TmegP/0lzJgXkF4n3tqG8M3MgI3ja Y4X613P6qsmeuG6SLOJvqt88Ud7dIbnOh8Uu0XnWbPupI7nJitfUH11fjS4qBNWr YgbULfF1Xx3cvjwoVUsw8PdpmVhpi5Ayi0UJx6wy5fNoND61LkTuIigDeKdB3E6Z QWAvz9TLKKFmM9hPu7ru4IbTN1KWmP6F1CmCeyuhbXoQB3oJkDH4AZjPMHwgU7sR HrbDXzHjkO105juAfK26bV5T1mvnzK4EPwGyCxW3RK4ZIQyLjjyXwxnuuTiMijLB 6JEGSS92r2GIOttHUrd8VWnpOZAPLtCujOucrx1ymAoS3p78UIqv+BjI/drMqnFr b9DRpeflOr9+OIUX/c5WhmQ0quGUtGbb8I/PAyV6VtnhOfn1bweH5NJ7XycFXKQ3 uU7/Oux2HoK9S1j6DKqgKqQJv6covR5KwM0/aB0Aq5P31hNW2l8MwKJAMKvSwviK gDGpbTA7755ghY8wzwkGKhXn/DAzRt8WPnNod4QQ7IMvqS5a7Id6MtXPLwLKllUX GxGLR4CngbNGE9gCrcA+AT7Nhj1BehMGi3vx0l9GOympXiEeDvVfn+0Sd9+uA19k 6KN2lib8olloMoOjxnXJ0kE0zCfacFXwHXCvNuZilRMyQ521F55bkCPEPSduaXiv pdDyFR+MH8Xs52MKaSaq =/gy6 -----END PGP SIGNATURE-----
--=-0AjihcceJqi5q/XUFhgR--
--===============4472500133395995111== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============4472500133395995111==--
|
|
|
|