CVE-2012-1053
published 2012-05-29CVE-2012-1053: The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE)…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.38%
30.7th percentile
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.11-1 (bullseye) | puppet 2.7.11-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.11-1 | 2.7.11-1 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-02-23·CVSS 6.9
CVE-2012-1053 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Puppet could be made to overwrite files and run programs with administrator
privileges.
It was discovered that Puppet did not drop privileges when executing
commands as different users. If an attacker had control of the execution
manifests or the executed command, this could be used to execute code with
elevated group permissions (typically root). (CVE-2012-1053)
It was discovered that Puppet unsafely opened files when the k5login type
is used to manage files. A local attacker could exploit this to overwrite
arbitrary files and escalate privileges. (CVE-2012-1054)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Puppet 2.6.13 group ID handling issues
vendor_redhat·2012-02-22·CVSS 6.9
CVE-2012-1053 [MEDIUM] Puppet 2.6.13 group ID handling issues
Puppet 2.6.13 group ID handling issues
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-1053: puppet - The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Pu...
vendor_debian·2012·CVSS 6.9
CVE-2012-1053 [MEDIUM] CVE-2012-1053: puppet - The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Pu...
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
Scope: local
bullseye: resolved (fixed in 2.7.11-1)
OSV
Puppet Privilege Escallation
osv·2022-05-14
CVE-2012-1053 [MEDIUM] Puppet Privilege Escallation
Puppet Privilege Escallation
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
GHSA
Puppet Privilege Escallation
ghsa·2022-05-14
CVE-2012-1053 [MEDIUM] CWE-269 Puppet Privilege Escallation
Puppet Privilege Escallation
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
OSV
CVE-2012-1053: The change_user method in the SUIDManager (lib/puppet/util/suidmanager
osv·2012-05-29·CVSS 6.9
CVE-2012-1053 [MEDIUM] CVE-2012-1053: The change_user method in the SUIDManager (lib/puppet/util/suidmanager
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1053 CVE-2012-1054 rhc-server various flaws [openshift-express-1]
bugzilla·2012-04-03·CVSS 6.9
CVE-2012-1053 [MEDIUM] CVE-2012-1053 CVE-2012-1054 rhc-server various flaws [openshift-express-1]
CVE-2012-1053 CVE-2012-1054 rhc-server various flaws [openshift-express-1]
openshift-express-1 tracking bug for rhc-server: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
OpenShift ships puppet 2.6.14, fixed.
Bugzilla
CVE-2012-1053 CVE-2012-1054 puppet various flaws [epel-all]
bugzilla·2012-03-10·CVSS 6.9
CVE-2012-1053 [MEDIUM] CVE-2012-1053 CVE-2012-1054 puppet various flaws [epel-all]
CVE-2012-1053 CVE-2012-1054 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=791001
Pl
Bugzilla
CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
bugzilla·2012-03-10·CVSS 2.6
CVE-2011-3872 [LOW] CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
CVE-2011-3872 CVE-2012-1053 CVE-2012-1054 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-1053 Puppet 2.6.13 group ID handling issues
bugzilla·2012-02-15·CVSS 6.9
CVE-2012-1053 [MEDIUM] CVE-2012-1053 Puppet 2.6.13 group ID handling issues
CVE-2012-1053 Puppet 2.6.13 group ID handling issues
There have been two vulnerabilities discovered in Puppet
(CVE-2012-1053 and CVE-2012-1054). Puppet Labs is currently working
with distribution
maintainers, as well as key customers to ensure we are able to patch
this vulnerability before it is exploited.
The CVEs and issues have not been made public yet. We appreciate your
discretion at this time. We have included patches for 2.6.x and 2.7.x.
If you need help with patches for other series or versions of Puppet,
please let us know.
# Summary #
(#12457, #12459) Execs, when run with a user specified but with no
group specified will get root group, so the exec then gets unintended
privileges. This is a permanent change for the forked process. Exploit
requires access to either the comman
Bugzilla
CVE-2012-1054 Puppet 2.6.13 Klogin File Handling Issue
bugzilla·2012-02-15·CVSS 6.9
CVE-2012-1054 [MEDIUM] CVE-2012-1054 Puppet 2.6.13 Klogin File Handling Issue
CVE-2012-1054 Puppet 2.6.13 Klogin File Handling Issue
There have been two vulnerabilities discovered in Puppet
(CVE-2012-1053 and CVE-2012-1054). Puppet Labs is currently working
with distribution
maintainers, as well as key customers to ensure we are able to patch
this vulnerability before it is exploited.
The CVEs and issues have not been made public yet. We appreciate your
discretion at this time. We have included patches for 2.6.x and 2.7.x.
If you need help with patches for other series or versions of Puppet,
please let us know.
# Summary #
(#12460) Klogin type will write to untrusted locations (write through symlinks)
#12460 - Klogin File Handling Issue (Write through symlink)
High risk for users of this type. Users can symlink to arbitrary files, causing
them to be overwritt
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.htmlhttp://projects.puppetlabs.com/issues/12457http://projects.puppetlabs.com/issues/12458http://projects.puppetlabs.com/issues/12459http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14http://puppetlabs.com/security/cve/cve-2012-1053/http://secunia.com/advisories/48157http://secunia.com/advisories/48161http://secunia.com/advisories/48166http://secunia.com/advisories/48290http://ubuntu.com/usn/usn-1372-1http://www.debian.org/security/2012/dsa-2419http://www.osvdb.org/79495http://www.securityfocus.com/bid/52158https://exchange.xforce.ibmcloud.com/vulnerabilities/73445https://hermes.opensuse.org/messages/15087408http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.htmlhttp://projects.puppetlabs.com/issues/12457http://projects.puppetlabs.com/issues/12458http://projects.puppetlabs.com/issues/12459http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14http://puppetlabs.com/security/cve/cve-2012-1053/http://secunia.com/advisories/48157http://secunia.com/advisories/48161http://secunia.com/advisories/48166http://secunia.com/advisories/48290http://ubuntu.com/usn/usn-1372-1http://www.debian.org/security/2012/dsa-2419http://www.osvdb.org/79495http://www.securityfocus.com/bid/52158https://exchange.xforce.ibmcloud.com/vulnerabilities/73445https://hermes.opensuse.org/messages/15087408
2012-05-29
Published