CVE-2011-3869
published 2011-10-27CVE-2011-3869: Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
PriorityP418medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.34%
26.4th percentile
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.3-3 (bullseye) | puppet 2.7.3-3 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.3-3 | 2.7.3-3 |
| puppet | puppet | >= 0 < 2.6.11 | 2.6.11 |
| puppet | puppet | >= 2.7.0 < 2.7.5 | 2.7.5 |
CVSS provenance
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet regression
vendor_ubuntu·2011-10-05·CVSS 6.3
[MEDIUM] Puppet regression
Title: Puppet regression
Summary: USN-1223-1 caused a regression with managing SSH authorized_keys files.
USN-1223-1 fixed vulnerabilities in Puppet. A regression was found on
Ubuntu 10.04 LTS that caused permission denied errors when managing SSH
authorized_keys files with Puppet. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Puppet unsafely opened files when the k5login type
is used to manage files. A local attacker could exploit this to overwrite
arbitrary files which could be used to escalate privileges. (CVE-2011-3869)
Ricky Zhou discovered that Puppet did not drop privileges when creating
SSH authorized_keys files. A local attacker could exploit this to overwrite
arbitrary files as root. (CVE-2011-3870)
It
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2011-09-30·CVSS 6.3
CVE-2011-3869 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Puppet could be made to overwrite files and run programs with administrator
privileges.
It was discovered that Puppet unsafely opened files when the k5login type
is used to manage files. A local attacker could exploit this to overwrite
arbitrary files which could be used to escalate privileges. (CVE-2011-3869)
Ricky Zhou discovered that Puppet did not drop privileges when creating
SSH authorized_keys files. A local attacker could exploit this to overwrite
arbitrary files as root. (CVE-2011-3870)
It was discovered that Puppet used a predictable filename when using the
--edit resource. A local attacker could exploit this to edit arbitrary
files or run arbitrary code as the user invoking the program, typically
root. (CVE-2011-3871)
Instructions: In
Red Hat
puppet: K5login content attack
vendor_redhat·2011-09-30·CVSS 6.3
CVE-2011-3869 [MEDIUM] puppet: K5login content attack
puppet: K5login content attack
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2011-3869: puppet - Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to...
vendor_debian·2011·CVSS 6.3
CVE-2011-3869 [MEDIUM] CVE-2011-3869: puppet - Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to...
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
Scope: local
bullseye: resolved (fixed in 2.7.3-3)
GHSA
Puppet arbitrary file overwrite
ghsa·2022-05-14
CVE-2011-3869 [MEDIUM] CWE-59 Puppet arbitrary file overwrite
Puppet arbitrary file overwrite
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
OSV
Puppet arbitrary file overwrite
osv·2022-05-14
CVE-2011-3869 [MEDIUM] Puppet arbitrary file overwrite
Puppet arbitrary file overwrite
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
OSV
CVE-2011-3869: Puppet 2
osv·2011-10-27·CVSS 6.3
CVE-2011-3869 [MEDIUM] CVE-2011-3869: Puppet 2
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue a
Bugzilla
CVE-2011-3869 puppet: K5login content attack
bugzilla·2011-09-30·CVSS 6.3
CVE-2011-3869 [MEDIUM] CVE-2011-3869 puppet: K5login content attack
CVE-2011-3869 puppet: K5login content attack
A flaw was found in the way puppet handled the k5login type. The k5login type is typically used to manage a file in the home directory of a user. It would write to the target file, as root, without doing anything to secure the file. This would allow the owner of the home directory to symlink to anything on the system, and have the contents replaced, as root.
This is corrected in upstream 2.6.11 and 2.7.5 releases.
Discussion:
Created attachment 525847
patch from upstream for 2.6.x and 2.7.x
---
Created attachment 525848
patch from upstream for 0.25.x
---
Created puppet tracking bugs for this issue
Affects: fedora-all [bug 742654]
Affects: epel-all [bug 742655]
---
puppet-0.25.5-2.el4 has been pushed to the Fedora EPEL 4 stable reposit
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue aff
http://groups.google.com/group/puppet-announce/browse_thread/thread/91e3b46d2328a1cbhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068053.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068093.htmlhttp://secunia.com/advisories/46458http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1223-1http://www.ubuntu.com/usn/USN-1223-2https://puppet.com/security/cve/cve-2011-3869http://groups.google.com/group/puppet-announce/browse_thread/thread/91e3b46d2328a1cbhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068053.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068093.htmlhttp://secunia.com/advisories/46458http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1223-1http://www.ubuntu.com/usn/USN-1223-2https://puppet.com/security/cve/cve-2011-3869
2011-10-27
Published