VulnerabilityModified
CVE-2013-4969
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
LOW 2.1EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- puppetlabs/puppet · puppet/puppet enterprise · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://puppetlabs.com/security/cve/cve-2013-4969Vendor Advisory
- http://secunia.com/advisories/56253Vendor Advisory
- http://secunia.com/advisories/56254Vendor Advisory
- http://www.debian.org/security/2013/dsa-2831Third Party Advisory
- http://www.ubuntu.com/usn/USN-2077-1Third Party Advisory
- http://puppetlabs.com/security/cve/cve-2013-4969Vendor Advisory
- http://secunia.com/advisories/56253Vendor Advisory
- http://secunia.com/advisories/56254Vendor Advisory
- http://www.debian.org/security/2013/dsa-2831Third Party Advisory
- http://www.ubuntu.com/usn/USN-2077-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.