CVE-2012-1906
published 2012-05-29CVE-2012-1906: Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names…
PriorityP411low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.35%
27.2th percentile
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.13-1 (bullseye) | puppet 2.7.13-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
puppet: Puppet uses predictable filenames, allowing arbitrary file overwrite
vendor_redhat·2012-05-29·CVSS 3.3
CVE-2012-1906 [LOW] puppet: Puppet uses predictable filenames, allowing arbitrary file overwrite
puppet: Puppet uses predictable filenames, allowing arbitrary file overwrite
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
Package: puppet (Red Hat OpenStack Platform 16.1) - Not affected
Package: puppet (Red Hat OpenStack Platform 16.2) - Not affected
Package: puppet (Red Hat OpenStack Platform 17.0) - Not affected
Package: puppet (Red Hat OpenStack Platform 17.1) - Not affected
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-04-11·CVSS 3.3
CVE-2012-1906 [LOW] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in puppet.
It was discovered that Puppet used a predictable filename when downloading Mac
OS X package files. A local attacker could exploit this to overwrite arbitrary
files. (CVE-2012-1906)
It was discovered that Puppet incorrectly handled filebucket retrieval
requests. A local attacker could exploit this to read arbitrary files.
(CVE-2012-1986)
It was discovered that Puppet incorrectly handled filebucket store requests. A
local attacker could exploit this to perform a denial of service via resource
exhaustion. (CVE-2012-1987)
It was discovered that Puppet incorrectly handled filebucket requests. A local
attacker could exploit this to execute arbitrary code via a crafted file path.
(CVE-2012-1988)
It was disc
Debian
CVE-2012-1906: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
vendor_debian·2012·CVSS 3.3
CVE-2012-1906 [LOW] CVE-2012-1906: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
GHSA
Puppet uses predictable filenames, allowing arbitrary file overwrite
ghsa·2022-05-14
CVE-2012-1906 [MEDIUM] CWE-377 Puppet uses predictable filenames, allowing arbitrary file overwrite
Puppet uses predictable filenames, allowing arbitrary file overwrite
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
OSV
Puppet uses predictable filenames, allowing arbitrary file overwrite
osv·2022-05-14
CVE-2012-1906 [MEDIUM] Puppet uses predictable filenames, allowing arbitrary file overwrite
Puppet uses predictable filenames, allowing arbitrary file overwrite
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
OSV
CVE-2012-1906: Puppet 2
osv·2012-05-29·CVSS 3.3
CVE-2012-1906 [LOW] CVE-2012-1906: Puppet 2
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://projects.puppetlabs.com/issues/13260http://puppetlabs.com/security/cve/cve-2012-1906/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74793http://projects.puppetlabs.com/issues/13260http://puppetlabs.com/security/cve/cve-2012-1906/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74793
2012-05-29
Published