CVE-2011-3872
published 2011-10-27CVE-2011-3872: Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the…
PriorityP414low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.45%
82.6th percentile
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.6-1 (bullseye) | puppet 2.7.6-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.6-1 | 2.7.6-1 |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppetlabs | puppet | — | — |
| puppetlabs | puppet | — | — |
| puppetlabs | puppet_enterprise_users | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2011-10-24
CVE-2011-3872 Puppet vulnerability
Title: Puppet vulnerability
Summary: The Puppet primary server could be impersonated in certain configurations.
It was discovered that Puppet incorrectly handled the non-default
"certdnsnames" option when generating certificates. If this setting was
added to puppet.conf, the puppet primary server’s DNS alt names were added
to the X.509 Subject Alternative Name field of all certificates, not just
the puppet primary server’s certificate. An attacker that has an incorrect
agent certificate in his possession can use it to impersonate the puppet
primary server in a machine-in-the-middle attack.
Instructions: In general, a standard system update will make all the necessary changes.
If your puppet primary server's puppet.conf file has ever contained the
"certdnsnames" setting, you must reissu
Red Hat
puppet: MITM by the x509v3 certificate signing
vendor_redhat·2011-10-24·CVSS 2.6
CVE-2011-3872 [LOW] puppet: MITM by the x509v3 certificate signing
puppet: MITM by the x509v3 certificate signing
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2011-3872: puppet - Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Us...
vendor_debian·2011·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872: puppet - Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Us...
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
Scope: local
bullseye: resolved (fixed in 2.7.6-1)
GHSA
GHSA-494g-9grq-m629: Puppet 2
ghsa_unreviewed·2022-05-14
CVE-2011-3872 [LOW] CWE-20 GHSA-494g-9grq-m629: Puppet 2
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
OSV
CVE-2011-3872: Puppet 2
osv·2011-10-27·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872: Puppet 2
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
bugzilla·2012-03-10·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [epel-all]
bugzilla·2011-10-25·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [epel-all]
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=748447
Please note: this issue affects multiple su
Bugzilla
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [fedora-all]
bugzilla·2011-10-25·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [fedora-all]
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=748447
Please note: this issue affects multiple
Bugzilla
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing
bugzilla·2011-10-24·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872 puppet: MITM by the x509v3 certificate signing
CVE-2011-3872 puppet: MITM by the x509v3 certificate signing
A security flaw was found in the way Puppet, a network tool for managing many disparate systems, recognized additional DNS names to be added to the certificate of the Puppet master, when that certicate was used for subsequent communication with Puppet clients. A remote, privileged user, with ability to modify the SSL certificate of the Puppet agent could use this flaw to impersonate main Puppet master server against Puppet clients (MITM).
Discussion:
This issue affects the versions of the puppet package, as shipped with Fedora release of 14 and 15.
--
This issue affects the versions of the puppet package, as shipped with Fedora EPEL 4, Fedora EPEL 5 and Fedora EPEL 6 releases.
---
Created attachment 529872
Local copy of pr
http://groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1http://puppetlabs.com/blog/important-security-announcement-altnames-vulnerability/http://secunia.com/advisories/46550http://secunia.com/advisories/46578http://secunia.com/advisories/46934http://secunia.com/advisories/46964http://www.securityfocus.com/bid/50356http://www.ubuntu.com/usn/USN-1238-1http://www.ubuntu.com/usn/USN-1238-2https://exchange.xforce.ibmcloud.com/vulnerabilities/70970https://puppet.com/security/cve/cve-2011-3872http://groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1http://puppetlabs.com/blog/important-security-announcement-altnames-vulnerability/http://secunia.com/advisories/46550http://secunia.com/advisories/46578http://secunia.com/advisories/46934http://secunia.com/advisories/46964http://www.securityfocus.com/bid/50356http://www.ubuntu.com/usn/USN-1238-1http://www.ubuntu.com/usn/USN-1238-2https://exchange.xforce.ibmcloud.com/vulnerabilities/70970https://puppet.com/security/cve/cve-2011-3872
2011-10-27
Published