CVE-2013-4969
published 2014-01-07CVE-2013-4969: Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.43%
34.7th percentile
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | puppet | < puppet 3.4.1-1 (bullseye) | puppet 3.4.1-1 (bullseye) |
| puppet | puppet | >= 0 < 3.4.1-1 | 3.4.1-1 |
| puppet | puppet_enterprise | >= 2.0.0 < 2.8.4 | 2.8.4 |
| puppet | puppet_enterprise | >= 3.1 < 3.1.1 | 3.1.1 |
| puppetlabs | puppet | 3.0.0 – 3.3.2 | — |
| puppetlabs | puppet | >= 3.4.0 < 3.4.1 | 3.4.1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-73jw-pjcv-9rgm: Puppet before 3
ghsa_unreviewed·2022-05-13
CVE-2013-4969 [LOW] CWE-59 GHSA-73jw-pjcv-9rgm: Puppet before 3
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
OSV
CVE-2013-4969: Puppet before 3
osv·2014-01-07·CVSS 2.1
CVE-2013-4969 [LOW] CVE-2013-4969: Puppet before 3
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2014-01-06
CVE-2013-4969 Puppet vulnerability
Title: Puppet vulnerability
Summary: Puppet could be made to overwrite files.
It was discovered that Puppet incorrectly handled temporary files. A local
attacker could possibly use this issue to overwrite arbitrary files. In the
default installation of Ubuntu, this should be prevented by the Yama link
restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Puppet: Unsafe use of Temp files in File type
vendor_redhat·2013-12-26·CVSS 2.1
CVE-2013-4969 [LOW] CWE-377 Puppet: Unsafe use of Temp files in File type
Puppet: Unsafe use of Temp files in File type
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Statement: Red Hat Product Security has rated this issue as having Low security impact in Subscription Asset Manager 1. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.
Package: puppet (CloudForms Management Engine 5) - No
Debian
CVE-2013-4969: puppet - Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4...
vendor_debian·2013·CVSS 2.1
CVE-2013-4969 [LOW] CVE-2013-4969: puppet - Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4...
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Scope: local
bullseye: resolved (fixed in 3.4.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4969 Puppet: Unsafe use of Temp files in File type [fedora-all]
bugzilla·2014-01-02·CVSS 2.1
CVE-2013-4969 [LOW] CVE-2013-4969 Puppet: Unsafe use of Temp files in File type [fedora-all]
CVE-2013-4969 Puppet: Unsafe use of Temp files in File type [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-4969 Puppet: Unsafe use of Temp files in File type
bugzilla·2013-12-19·CVSS 2.1
CVE-2013-4969 [LOW] CVE-2013-4969 Puppet: Unsafe use of Temp files in File type
CVE-2013-4969 Puppet: Unsafe use of Temp files in File type
Moses Mendoza of Puppet Labs reports:
Unsafe use of Temp files in File type (Local Privilege Escalation)
Assessed Risk Level: Medium
Puppet uses temp files unsafely by looking for a name it can use in a
directory, and then later writing to that file, creating a
vulnerability in which an attacker could make the name a symlink to
another file and thereby cause the puppet agent to overwrite something
that it did not intend to. The degree of difficulty to exploit this
vulnerability is high. We have not actually exploited this
vulnerability successfully.
Discussion:
Created attachment 839245
CVE-2013-4969-2.7.x-temp-file.patch
---
Created attachment 839246
CVE-2013-4969-3.3.x-temp-file.patch
---
External References:
http://pup
Bugzilla
CVE-2011-4969 jquery: Cross-site scripting (XSS) via $(location.hash) and $(#<tag>)
bugzilla·2013-02-01·CVSS 4.3
CVE-2011-4969 [MEDIUM] CVE-2011-4969 jquery: Cross-site scripting (XSS) via $(location.hash) and $(#<tag>)
CVE-2011-4969 jquery: Cross-site scripting (XSS) via $(location.hash) and $(#)
A cross-site scripting (XSS) flaw was found in the way jQuery, a fast, small, and feature-rich JavaScript library, performed sanitization of location.hash and arguments in certain circumstances. A remote attacker could provide a specially-crafted web page to a web-based application using the jQuery library that, when processed would lead to arbitrary HTML or web script execution in the context of logged-in user session.
Upstream bug report:
[1] http://bugs.jquery.com/ticket/9521
References:
[2] http://blog.jquery.com/2011/09/01/jquery-1-6-3-released/
[3] http://www.openwall.com/lists/oss-security/2013/01/31/3
Discussion:
Created drupal7-jquery_update tracking bugs for this issue
Affects: fedora-all [bug 89
http://puppetlabs.com/security/cve/cve-2013-4969http://secunia.com/advisories/56253http://secunia.com/advisories/56254http://www.debian.org/security/2013/dsa-2831http://www.ubuntu.com/usn/USN-2077-1http://puppetlabs.com/security/cve/cve-2013-4969http://secunia.com/advisories/56253http://secunia.com/advisories/56254http://www.debian.org/security/2013/dsa-2831http://www.ubuntu.com/usn/USN-2077-1
2014-01-07
Published