CVE-2012-1987
published 2012-05-29CVE-2012-1987: Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before…
PriorityP419low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
2.55%
83.3th percentile
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.13-1 (bullseye) | puppet 2.7.13-1 (bullseye) |
| puppet | puppet | >= 0 < 2.7.13-1 | 2.7.13-1 |
| puppet | puppet | >= 2.6.0 < 2.6.15 | 2.6.15 |
| puppet | puppet | >= 2.6.0 < 2.6.15 | 2.6.15 |
| puppet | puppet | >= 2.7.0 < 2.7.13 | 2.7.13 |
| puppet | puppet | >= 2.7.0 < 2.7.13 | 2.7.13 |
| puppet | puppet_enterprise | >= 1.0 < 2.5.1 | 2.5.1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
ghsa2.1LOW
osv2.1LOW
vendor_ubuntu3.3LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Puppet Denial of Service and Arbitrary File Write
osv·2022-05-14·CVSS 2.1
CVE-2012-1987 [LOW] Puppet Denial of Service and Arbitrary File Write
Puppet Denial of Service and Arbitrary File Write
A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a `Puppet::FileBucket::File object`" to write to arbitrary file locations.
GHSA
Puppet Denial of Service and Arbitrary File Write
ghsa·2022-05-14·CVSS 2.1
CVE-2012-1987 [LOW] CWE-400 Puppet Denial of Service and Arbitrary File Write
Puppet Denial of Service and Arbitrary File Write
A vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to **(1)** cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and `/dev/random`; or **(2)** cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a `Puppet::FileBucket::File object`" to write to arbitrary file locations.
OSV
CVE-2012-1987: Unspecified vulnerability in Puppet 2
osv·2012-05-29·CVSS 2.1
CVE-2012-1987 [LOW] CVE-2012-1987: Unspecified vulnerability in Puppet 2
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-04-11·CVSS 3.3
CVE-2012-1906 [LOW] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in puppet.
It was discovered that Puppet used a predictable filename when downloading Mac
OS X package files. A local attacker could exploit this to overwrite arbitrary
files. (CVE-2012-1906)
It was discovered that Puppet incorrectly handled filebucket retrieval
requests. A local attacker could exploit this to read arbitrary files.
(CVE-2012-1986)
It was discovered that Puppet incorrectly handled filebucket store requests. A
local attacker could exploit this to perform a denial of service via resource
exhaustion. (CVE-2012-1987)
It was discovered that Puppet incorrectly handled filebucket requests. A local
attacker could exploit this to execute arbitrary code via a crafted file path.
(CVE-2012-1988)
It was disc
Red Hat
puppet: Filebucket denial of service
vendor_redhat·2012-04-10·CVSS 2.1
CVE-2012-1987 [LOW] puppet: Filebucket denial of service
puppet: Filebucket denial of service
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Package: puppet (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-1987: puppet - Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13,...
vendor_debian·2012·CVSS 2.1
CVE-2012-1987 [LOW] CVE-2012-1987: puppet - Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13,...
Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
bugzilla·2012-04-16·CVSS 2.1
CVE-2012-1986 [LOW] CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 puppet various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-1987 puppet: Filebucket denial of service
bugzilla·2012-04-05·CVSS 3.5
CVE-2012-1987 [LOW] CVE-2012-1987 puppet: Filebucket denial of service
CVE-2012-1987 puppet: Filebucket denial of service
From Matthaus Litteken :
CVE-2012-1987 (Moderate) [#13552,#13553] - Filebucket denial of service
By constructing a marshaled form of a Puppet::FileBucket::File object
a user can cause it it to be written to any place on the disk of the
puppet master. This could be used for a denial of service attach
against the puppet master if an attacker fills a filesystem that can
cause systems to stop working. In order to do this the attacker needs
no access to the puppet master system, but does need access to agent
SSL keys.
Discussion:
This is public now.
External Reference:
http://puppetlabs.com/security/cve/cve-2012-1987/
---
Created puppet tracking bugs for this issue
Affects: fedora-all [bug 812955]
Affects: epel-all [bug 812956]
---
A
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13552http://projects.puppetlabs.com/issues/13553http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1987/http://puppetlabs.com/security/cve/cve-2012-1987/hotfixes/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.osvdb.org/81308http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74794https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.htmlhttp://projects.puppetlabs.com/issues/13552http://projects.puppetlabs.com/issues/13553http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15http://puppetlabs.com/security/cve/cve-2012-1987/http://puppetlabs.com/security/cve/cve-2012-1987/hotfixes/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/48789http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.debian.org/security/2012/dsa-2451http://www.osvdb.org/81308http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74794https://hermes.opensuse.org/messages/14523305https://hermes.opensuse.org/messages/15087408
2012-05-29
Published