CVE-2012-1906
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
- CVSS 2.0
- 3.3 LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- puppet/puppet · puppet/puppet enterprise · puppetlabs/puppet · puppetlabs/puppet enterprise users
- Source
- cve@mitre.org
References
- http://projects.puppetlabs.com/issues/13260Vendor Advisory
- http://puppetlabs.com/security/cve/cve-2012-1906/Vendor Advisory
- http://secunia.com/advisories/48743Vendor Advisory
- http://secunia.com/advisories/48748Vendor Advisory
- http://secunia.com/advisories/48789Vendor Advisory
- http://ubuntu.com/usn/usn-1419-1
- http://www.debian.org/security/2012/dsa-2451
- http://www.securityfocus.com/bid/52975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74793
- http://projects.puppetlabs.com/issues/13260Vendor Advisory
- http://puppetlabs.com/security/cve/cve-2012-1906/Vendor Advisory
- http://secunia.com/advisories/48743Vendor Advisory
- http://secunia.com/advisories/48748Vendor Advisory
- http://secunia.com/advisories/48789Vendor Advisory
- http://ubuntu.com/usn/usn-1419-1
- http://www.debian.org/security/2012/dsa-2451
- http://www.securityfocus.com/bid/52975
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74793
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.