CVE-2011-3869Link Following in Puppet

CWE-59Link Following11 documents8 sources
Severity
6.3MEDIUMNVD
EPSS
0.0%
top 87.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 14

Description

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to overwrite arbitrary files via a symlink attack on the .k5login file.

CVSS vector

AV:L/AC:M/C:N/I:C/A:CExploitability: 3.4 | Impact: 9.2

Affected Packages4 packages

RubyGemspuppet/puppet2.7.02.7.5+1
Debianpuppet/puppet< 2.7.3-3
NVDpuppet/puppet21 versions+20
NVDpuppetlabs/puppet2.7.0, 2.7.1+1

Patches

🔴Vulnerability Details

4
GHSA
Puppet arbitrary file overwrite2022-05-14
OSV
Puppet arbitrary file overwrite2022-05-14
CVEList
CVE-2011-3869: Puppet 22011-10-27
OSV
CVE-2011-3869: Puppet 22011-10-27

📋Vendor Advisories

3
Ubuntu
Puppet vulnerabilities2011-09-30
Red Hat
puppet: K5login content attack2011-09-30
Debian
CVE-2011-3869: puppet - Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to...2011

💬Community

3
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]2011-09-30
Bugzilla
CVE-2011-3869 puppet: K5login content attack2011-09-30
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]2011-09-30
CVE-2011-3869 — Link Following in Puppet | cvebase