CVE-2011-3870
published 2011-10-27CVE-2011-3870: Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH…
PriorityP419medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.35%
27.6th percentile
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.3-3 (bullseye) | puppet 2.7.3-3 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.3-3 | 2.7.3-3 |
| puppet | puppet | >= 0 < 2.6.11 | 2.6.11 |
| puppet | puppet | >= 2.7.0 < 2.7.5 | 2.7.5 |
CVSS provenance
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet regression
vendor_ubuntu·2011-10-05·CVSS 6.3
[MEDIUM] Puppet regression
Title: Puppet regression
Summary: USN-1223-1 caused a regression with managing SSH authorized_keys files.
USN-1223-1 fixed vulnerabilities in Puppet. A regression was found on
Ubuntu 10.04 LTS that caused permission denied errors when managing SSH
authorized_keys files with Puppet. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Puppet unsafely opened files when the k5login type
is used to manage files. A local attacker could exploit this to overwrite
arbitrary files which could be used to escalate privileges. (CVE-2011-3869)
Ricky Zhou discovered that Puppet did not drop privileges when creating
SSH authorized_keys files. A local attacker could exploit this to overwrite
arbitrary files as root. (CVE-2011-3870)
It
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2011-09-30·CVSS 6.3
CVE-2011-3869 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Puppet could be made to overwrite files and run programs with administrator
privileges.
It was discovered that Puppet unsafely opened files when the k5login type
is used to manage files. A local attacker could exploit this to overwrite
arbitrary files which could be used to escalate privileges. (CVE-2011-3869)
Ricky Zhou discovered that Puppet did not drop privileges when creating
SSH authorized_keys files. A local attacker could exploit this to overwrite
arbitrary files as root. (CVE-2011-3870)
It was discovered that Puppet used a predictable filename when using the
--edit resource. A local attacker could exploit this to edit arbitrary
files or run arbitrary code as the user invoking the program, typically
root. (CVE-2011-3871)
Instructions: In
Red Hat
puppet: SSH authorized_keys symlink attack
vendor_redhat·2011-09-30·CVSS 6.3
CVE-2011-3870 [MEDIUM] puppet: SSH authorized_keys symlink attack
puppet: SSH authorized_keys symlink attack
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2011-3870: puppet - Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to...
vendor_debian·2011·CVSS 6.3
CVE-2011-3870 [MEDIUM] CVE-2011-3870: puppet - Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to...
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
Scope: local
bullseye: resolved (fixed in 2.7.3-3)
OSV
Puppet allows local users to modify the permissions of arbitrary files
osv·2022-05-14
CVE-2011-3870 [MEDIUM] Puppet allows local users to modify the permissions of arbitrary files
Puppet allows local users to modify the permissions of arbitrary files
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
GHSA
Puppet allows local users to modify the permissions of arbitrary files
ghsa·2022-05-14
CVE-2011-3870 [MEDIUM] CWE-59 Puppet allows local users to modify the permissions of arbitrary files
Puppet allows local users to modify the permissions of arbitrary files
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
OSV
CVE-2011-3870: Puppet 2
osv·2011-10-27·CVSS 6.3
CVE-2011-3870 [MEDIUM] CVE-2011-3870: Puppet 2
Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x allows local users to modify the permissions of arbitrary files via a symlink attack on the SSH authorized_keys file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue a
Bugzilla
CVE-2011-3870 puppet: SSH authorized_keys symlink attack
bugzilla·2011-09-30·CVSS 6.3
CVE-2011-3870 [MEDIUM] CVE-2011-3870 puppet: SSH authorized_keys symlink attack
CVE-2011-3870 puppet: SSH authorized_keys symlink attack
A race condition was found in the way puppet handled ssh_authorized_keys. If a user's authorized_keys file was managed, they could use this flaw to overwrite arbitrary files as root when the target directory and file did not exist. Puppet would create the directory, ensure that is was user-writable, then wrote the file as the user before changing the file ownership. In the time between the write and chown/chmod operation, a user could replace the file with a symbolic link and have the operation apply to any file on the disk, as root.
This is corrected in upstream 2.6.11 and 2.7.5 releases.
Acknowledgements:
Red Hat would like to thank the Puppet team for reporting this issue. Upstream acknowledges Ricky Zhou as the original repo
Bugzilla
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
bugzilla·2011-09-30·CVSS 5.0
CVE-2011-3870 [MEDIUM] CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
CVE-2011-3870 CVE-2011-3869 CVE-2011-3871 CVE-2011-3848 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=742644
Please note: this issue aff
http://groups.google.com/group/puppet-announce/browse_thread/thread/91e3b46d2328a1cbhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068053.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068093.htmlhttp://secunia.com/advisories/46458http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1223-1http://www.ubuntu.com/usn/USN-1223-2https://puppet.com/security/cve/cve-2011-3870http://groups.google.com/group/puppet-announce/browse_thread/thread/91e3b46d2328a1cbhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068053.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068061.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-October/068093.htmlhttp://secunia.com/advisories/46458http://www.debian.org/security/2011/dsa-2314http://www.ubuntu.com/usn/USN-1223-1http://www.ubuntu.com/usn/USN-1223-2https://puppet.com/security/cve/cve-2011-3870
2011-10-27
Published