Login
Newsletter
Werbung

Sicherheit: Mangelnde Prüfung von Zertifikaten in Puppet (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Mangelnde Prüfung von Zertifikaten in Puppet (Aktualisierung)
ID: USN-1238-2
Distribution: Ubuntu
Plattformen: Ubuntu 11.04
Datum: Mi, 26. Oktober 2011, 14:33
Referenzen: Keine Angabe
Applikationen: Puppet
Update von: Mangelnde Prüfung von Zertifikaten in Puppet

Originalnachricht


--===============4472500133395995111==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-0AjihcceJqi5q/XUFhgR"


--=-0AjihcceJqi5q/XUFhgR
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1238-2
October 25, 2011

puppet regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04

Summary:

USN-1238-1 caused a regression on Ubuntu 11.04.

Software Description:
- puppet: Centralized configuration management

Details:

USN-1238-1 fixed vulnerabilities in Puppet. The upstream patch introduced a
regression in Ubuntu 11.04 when executing certain commands. This update
fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Puppet incorrectly handled the non-default
"certdnsnames" option when generating certificates. If this setting
was
added to puppet.conf, the puppet master’s DNS alt names were added to the
X.509 Subject Alternative Name field of all certificates, not just the
puppet master’s certificate. An attacker that has an incorrect agent
certificate in his possession can use it to impersonate the puppet master
in a man-in-the-middle attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
puppet-common 2.6.4-2ubuntu2.6

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1238-2
http://www.ubuntu.com/usn/usn-1238-1
https://launchpad.net/bugs/881361

Package Information:
https://launchpad.net/ubuntu/+source/puppet/2.6.4-2ubuntu2.6



--ÐAjihcceJqi5q/XUFhgR
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOpwnNAAoJEGVp2FWnRL6TmegP/0lzJgXkF4n3tqG8M3MgI3ja
Y4X613P6qsmeuG6SLOJvqt88Ud7dIbnOh8Uu0XnWbPupI7nJitfUH11fjS4qBNWr
YgbULfF1Xx3cvjwoVUsw8PdpmVhpi5Ayi0UJx6wy5fNoND61LkTuIigDeKdB3E6Z
QWAvz9TLKKFmM9hPu7ru4IbTN1KWmP6F1CmCeyuhbXoQB3oJkDH4AZjPMHwgU7sR
HrbDXzHjkO105juAfK26bV5T1mvnzK4EPwGyCxW3RK4ZIQyLjjyXwxnuuTiMijLB
6JEGSS92r2GIOttHUrd8VWnpOZAPLtCujOucrx1ymAoS3p78UIqv+BjI/drMqnFr
b9DRpeflOr9+OIUX/c5WhmQ0quGUtGbb8I/PAyV6VtnhOfn1bweH5NJ7XycFXKQ3
uU7/Oux2HoK9S1j6DKqgKqQJv6covR5KwM0/aB0Aq5P31hNW2l8MwKJAMKvSwviK
gDGpbTA7755ghY8wzwkGKhXn/DAzRt8WPnNod4QQ7IMvqS5a7Id6MtXPLwLKllUX
GxGLR4CngbNGE9gCrcA+AT7Nhj1BehMGi3vx0l9GOympXiEeDvVfn+0Sd9+uA19k
6KN2lib8olloMoOjxnXJ0kE0zCfacFXwHXCvNuZilRMyQ521F55bkCPEPSduaXiv
pdDyFR+MH8Xs52MKaSaq
=/gy6
-----END PGP SIGNATURE-----

--=-0AjihcceJqi5q/XUFhgR--



--===============4472500133395995111==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============4472500133395995111==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung