CVE-2009-3564
published 2009-10-06CVE-2009-3564: puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted…
PriorityP412medium4.7CVSS 2.0
AVLACMAuNCCINAN
EPSS
0.38%
30.3th percentile
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 0.25.1-3 (bullseye) | puppet 0.25.1-3 (bullseye) |
| puppet | puppet | >= 0 < 0.25.1-3 | 0.25.1-3 |
| reductivelabs | puppet | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:C/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6384-2w9h-qw8w: puppetmasterd in puppet 0
ghsa_unreviewed·2022-05-02
CVE-2009-3564 [MEDIUM] GHSA-6384-2w9h-qw8w: puppetmasterd in puppet 0
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
OSV
CVE-2009-3564: puppetmasterd in puppet 0
osv·2009-10-06·CVSS 4.7
CVE-2009-3564 [MEDIUM] CVE-2009-3564: puppetmasterd in puppet 0
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2010-03-24·CVSS 4.7
CVE-2010-0156 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Puppet vulnerabilities
It was discovered that Puppet did not drop supplementary groups when being
run as a different user. A local user may be able to use this flaw to
bypass security restrictions and gain access to restricted files.
(CVE-2009-3564)
It was discovered that Puppet did not correctly handle temporary files. A
local user can exploit this flaw to bypass security restrictions and
overwrite arbitrary files. (CVE-2010-0156)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2009-3564: puppet - puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switc...
vendor_debian·2009·CVSS 4.7
CVE-2009-3564 [MEDIUM] CVE-2009-3564: puppet - puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switc...
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Scope: local
bullseye: resolved (fixed in 0.25.1-3)
Red Hat
puppetmasterd does not initialize supplementary groups
vendor_redhat·2008-12-08·CVSS 4.7
CVE-2009-3564 [MEDIUM] puppetmasterd does not initialize supplementary groups
puppetmasterd does not initialize supplementary groups
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Statement: The Red Hat Security Response Team does not currently plan to fix this flaw in MRG.
No detection rules found.
No public exploits indexed.
2009-10-06
Published