CVE-2012-1986
published 2012-05-29CVE-2012-1986: Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated…
PriorityP417low2.1CVSS 2.0
AVNACHAuSCPINAN
EPSS
1.47%
70.9th percentile
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.13-1 (bullseye) | puppet 2.7.13-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
CVSS provenance
nvdv2.02.1LOWAV:N/AC:H/Au:S/C:P/I:N/A:N
ghsa2.1LOW
osv2.1LOW
vendor_ubuntu3.3LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Puppet Denial of Service and Arbitrary File Write
osv·2022-05-14·CVSS 2.1
CVE-2012-1987 [LOW] Puppet Denial of Service and Arbitrary File Write
Puppet Denial of Service and Arbitrary File Write
A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a `Puppet::FileBucket::File object`" to write to arbitrary file locations.
GHSA
GHSA-2crf-gcjf-2wmp: Puppet 2
ghsa_unreviewed·2022-05-14
CVE-2012-1986 [LOW] GHSA-2crf-gcjf-2wmp: Puppet 2
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
GHSA
Puppet Denial of Service and Arbitrary File Write
ghsa·2022-05-14·CVSS 2.1
CVE-2012-1987 [LOW] CWE-400 Puppet Denial of Service and Arbitrary File Write
Puppet Denial of Service and Arbitrary File Write
A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a `Puppet::FileBucket::File object`" to write to arbitrary file locations.
OSV
CVE-2012-1987: Unspecified vulnerability in Puppet 2
osv·2012-05-29·CVSS 2.1
CVE-2012-1987 [LOW] CVE-2012-1987: Unspecified vulnerability in Puppet 2
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
OSV
CVE-2012-1986: Puppet 2
osv·2012-05-29·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986: Puppet 2
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-04-11·CVSS 3.3
CVE-2012-1906 [LOW] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in puppet.
It was discovered that Puppet used a predictable filename when downloading Mac
OS X package files. A local attacker could exploit this to overwrite arbitrary
files. (CVE-2012-1906)
It was discovered that Puppet incorrectly handled filebucket retrieval
requests. A local attacker could exploit this to read arbitrary files.
(CVE-2012-1986)
It was discovered that Puppet incorrectly handled filebucket store requests. A
local attacker could exploit this to perform a denial of service via resource
exhaustion. (CVE-2012-1987)
It was discovered that Puppet incorrectly handled filebucket requests. A local
attacker could exploit this to execute arbitrary code via a crafted file path.
(CVE-2012-1988)
It was disc
Red Hat
puppet: Filebucket arbitrary file read
vendor_redhat·2012-04-10·CVSS 2.1
CVE-2012-1986 [LOW] puppet: Filebucket arbitrary file read
puppet: Filebucket arbitrary file read
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Red Hat
puppet: Filebucket denial of service
vendor_redhat·2012-04-10·CVSS 2.1
CVE-2012-1987 [LOW] puppet: Filebucket denial of service
puppet: Filebucket denial of service
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-1986: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
vendor_debian·2012·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986: puppet - Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) U...
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and certain permissions on the puppet master to read arbitrary files via a symlink attack in conjunction with a crafted REST request for a file in a filebucket.
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
Debian
CVE-2012-1987: puppet - Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13,...
vendor_debian·2012·CVSS 2.1
CVE-2012-1987 [LOW] CVE-2012-1987: puppet - Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13,...
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6617 qffmpeg/ffmpeg-spice: DoS via vectors related to the rtp format in ffserver.c
bugzilla·2013-12-26·CVSS 4.3
CVE-2012-6617 [MEDIUM] CVE-2012-6617 qffmpeg/ffmpeg-spice: DoS via vectors related to the rtp format in ffserver.c
CVE-2012-6617 qffmpeg/ffmpeg-spice: DoS via vectors related to the rtp format in ffserver.c
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6617 to the following vulnerability:
Name: CVE-2012-6617
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6617
Assigned: 20131224
Reference: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=9929991da7b843e7d80154fcacc4e80579b86a2d
Reference: http://www.ffmpeg.org/security.html
Reference: https://trac.ffmpeg.org/ticket/1986
Reference: OSVDB:93232
Reference: http://www.osvdb.org/93232
Reference: SECUNIA:51964
Reference: http://secunia.com/advisories/51964
The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the r
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-1986 puppet: Filebucket arbitrary file read
bugzilla·2012-04-05·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 puppet: Filebucket arbitrary file read
CVE-2012-1986 puppet: Filebucket arbitrary file read
From Matthaus Litteken :
CVE-2012-1986 (High) [#13511] - Filebucket arbitrary file read
it is possible to construct a REST request to fetch a file from a
filebucket that overrides the puppet master’s defined location
for the files to be stored. If a user has access to construct
directories and symlinks on the machine they can read any file
that the user the puppet master is running as has access to.
Using the symlink attack described in Bug #13511 the puppet master
can be caused to read from a stream (e.g. /dev/random) when
either trying to save a file or read a file. Because of the way
in which the puppet master deals with sending files on the
filesystem to a remote system via a REST request the thread
handling the request will block
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13511http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1986/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74794https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13511http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1986/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74794https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408
2012-05-29
Published