USN-1217-1: Puppet vulnerability
29 September 2011
An attacker could send crafted input to puppet and cause it to overwrite files.
Releases
Packages
- puppet - centralised configuration management for networks
Details
Kristian Erik Hermansen discovered a directory traversal vulnerability in
the SSLFile indirection base class. A remote attacker could exploit this to
overwrite files with the privileges of the Puppet Master.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.04
Ubuntu 10.10
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.