CVE-2010-0156
published 2010-03-03CVE-2010-0156: Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2)…
PriorityP47low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.33%
24.9th percentile
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 0.25.4-2 (bullseye) | puppet 0.25.4-2 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 0.25.4-2 | 0.25.4-2 |
| puppet | puppet | >= 0.24.0 < 0.24.9 | 0.24.9 |
| puppet | puppet | >= 0.25.0 < 0.25.2 | 0.25.2 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_ubuntu4.7MEDIUM
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2010-03-24·CVSS 4.7
CVE-2010-0156 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Puppet vulnerabilities
It was discovered that Puppet did not drop supplementary groups when being
run as a different user. A local user may be able to use this flaw to
bypass security restrictions and gain access to restricted files.
(CVE-2009-3564)
It was discovered that Puppet did not correctly handle temporary files. A
local user can exploit this flaw to bypass security restrictions and
overwrite arbitrary files. (CVE-2010-0156)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2010-0156: puppet - Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overw...
vendor_debian·2010·CVSS 3.3
CVE-2010-0156 [LOW] CVE-2010-0156: puppet - Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overw...
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
Scope: local
bullseye: resolved (fixed in 0.25.4-2)
OSV
Puppet arbitrary files overwrite via a symlink attack
osv·2022-05-02
CVE-2010-0156 [LOW] Puppet arbitrary files overwrite via a symlink attack
Puppet arbitrary files overwrite via a symlink attack
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
GHSA
Puppet arbitrary files overwrite via a symlink attack
ghsa·2022-05-02
CVE-2010-0156 [LOW] CWE-59 Puppet arbitrary files overwrite via a symlink attack
Puppet arbitrary files overwrite via a symlink attack
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
OSV
CVE-2010-0156: Puppet 0
osv·2010-03-03·CVSS 3.3
CVE-2010-0156 [LOW] CVE-2010-0156: Puppet 0
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1191 Sahana: Authentication bypass via "acl_enable_acl" URLs
bugzilla·2010-03-19·CVSS 6.4
CVE-2010-1191 [MEDIUM] CVE-2010-1191 Sahana: Authentication bypass via "acl_enable_acl" URLs
CVE-2010-1191 Sahana: Authentication bypass via "acl_enable_acl" URLs
Christopher showed:
[1] http://archives.neohapsis.com/archives/bugtraq/2010-03/0156.html
a deficiency in the way, Sahana disaster management system
performed user authentication. Visiting a certain URL
would allow an attacker to view (and potentially modify)
information, which should be otherwise protected by authentication.
Upstream bug report:
[2] http://sourceforge.net/tracker/?func=detail&aid=2970786&group_id=127855&atid=709778
References:
[3] http://archives.neohapsis.com/archives/bugtraq/2010-03/0156.html
[4] http://secunia.com/advisories/39020/
Affected versions:
Issue reported against v0.6.2.2. Other versions may be also affected.
Credit:
Christopher
CVE Request:
[5] http://www.openwall.com/lists/oss-secur
Bugzilla
CVE-2010-0156 puppet: several insecure tempfile creation issues
bugzilla·2009-05-27·CVSS 3.3
CVE-2010-0156 [LOW] CVE-2010-0156 puppet: several insecure tempfile creation issues
CVE-2010-0156 puppet: several insecure tempfile creation issues
Description of problem:
I noticed that puppet may create several predictable files in /tmp, e.g.
/tmp/daemonout
/tmp/puppetdoc.txt
/tmp/puppetdoc.tex
There are also a lot more in the tests, but they may not be run in Fedora's F10 spec, and even more in the puppet source, e.g. for the dmg installation provider.
Version-Release number of selected component (if applicable):
puppet-0.24.8-1.fc10
How reproducible:
always
Steps to Reproduce:
1. grep -nR /tmp/ /usr/lib/ruby/site_ruby/1.8/puppet
Actual results:
Contains ruby code like:
/usr/lib/ruby/site_ruby/1.8/puppet/daemon.rb:33: File.open("/tmp/daemonout", "w") { |f|
Expected results:
Should only report findings that are not executed, e.g. in comments or help information
http://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6cbf6087http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b2896d986c2http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036083.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036166.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38766https://bugzilla.redhat.com/show_bug.cgi?id=502881https://puppet.com/security/cve/cve-2010-0156http://groups.google.com/group/puppet-announce/browse_thread/thread/4401823f6cbf6087http://groups.google.com/group/puppet-announce/browse_thread/thread/73cd1b2896d986c2http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036083.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036166.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/38766https://bugzilla.redhat.com/show_bug.cgi?id=502881https://puppet.com/security/cve/cve-2010-0156
2010-03-03
Published