CVE-2012-1989
published 2012-06-27CVE-2012-1989: telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.40%
32.5th percentile
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | < puppet 2.7.13-1 (bullseye) | puppet 2.7.13-1 (bullseye) |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | — | — |
| puppet | puppet | >= 0 < 2.7.13-1 | 2.7.13-1 |
| puppet | puppet | >= 2.7.1 < 2.7.13 | 2.7.13 |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppetlabs | puppet | — | — |
| puppetlabs | puppet | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Puppet allows local users to overwrite arbitrary files via a symlink attack
ghsa·2017-10-24
CVE-2012-1989 [LOW] Puppet allows local users to overwrite arbitrary files via a symlink attack
Puppet allows local users to overwrite arbitrary files via a symlink attack
`telnet.rb` in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (`/tmp/out.log`).
OSV
Puppet allows local users to overwrite arbitrary files via a symlink attack
osv·2017-10-24
CVE-2012-1989 [LOW] Puppet allows local users to overwrite arbitrary files via a symlink attack
Puppet allows local users to overwrite arbitrary files via a symlink attack
`telnet.rb` in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (`/tmp/out.log`).
OSV
CVE-2012-1989: telnet
osv·2012-06-27·CVSS 3.6
CVE-2012-1989 [LOW] CVE-2012-1989: telnet
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Red Hat
puppet: Insecure temporary file use for NET::Telnet connection log (/tmp/out.log)
vendor_redhat·2012-04-11·CVSS 3.6
CVE-2012-1989 [LOW] CWE-377 puppet: Insecure temporary file use for NET::Telnet connection log (/tmp/out.log)
puppet: Insecure temporary file use for NET::Telnet connection log (/tmp/out.log)
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Package: puppet (Red Hat Enterprise MRG 1) - Not affected
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2012-04-11·CVSS 3.3
CVE-2012-1906 [LOW] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in puppet.
It was discovered that Puppet used a predictable filename when downloading Mac
OS X package files. A local attacker could exploit this to overwrite arbitrary
files. (CVE-2012-1906)
It was discovered that Puppet incorrectly handled filebucket retrieval
requests. A local attacker could exploit this to read arbitrary files.
(CVE-2012-1986)
It was discovered that Puppet incorrectly handled filebucket store requests. A
local attacker could exploit this to perform a denial of service via resource
exhaustion. (CVE-2012-1987)
It was discovered that Puppet incorrectly handled filebucket requests. A local
attacker could exploit this to execute arbitrary code via a crafted file path.
(CVE-2012-1988)
It was disc
Debian
CVE-2012-1989: puppet - telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x,...
vendor_debian·2012·CVSS 3.6
CVE-2012-1989 [LOW] CVE-2012-1989: puppet - telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x,...
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Scope: local
bullseye: resolved (fixed in 2.7.13-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2012-05/msg00012.htmlhttp://projects.puppetlabs.com/issues/13606http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.7.13http://puppetlabs.com/security/cve/cve-2012-1989/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74797https://hermes.opensuse.org/messages/15087408http://lists.opensuse.org/opensuse-updates/2012-05/msg00012.htmlhttp://projects.puppetlabs.com/issues/13606http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.7.13http://puppetlabs.com/security/cve/cve-2012-1989/http://secunia.com/advisories/48743http://secunia.com/advisories/48748http://secunia.com/advisories/49136http://ubuntu.com/usn/usn-1419-1http://www.securityfocus.com/bid/52975https://exchange.xforce.ibmcloud.com/vulnerabilities/74797https://hermes.opensuse.org/messages/15087408
2012-06-27
Published