![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2012-1906 |
Description: | Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.71255 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2012-1906 BugTraq ID: 52975 http://www.securityfocus.com/bid/52975 Debian Security Information: DSA-2451 (Google Search) http://www.debian.org/security/2012/dsa-2451 http://projects.puppetlabs.com/issues/13260 http://secunia.com/advisories/48743 http://secunia.com/advisories/48748 http://secunia.com/advisories/48789 http://ubuntu.com/usn/usn-1419-1 XForce ISS Database: puppet-macosx-symlink(74793) https://exchange.xforce.ibmcloud.com/vulnerabilities/74793 |