CVE-2017-10689
published 2018-02-09CVE-2017-10689: In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.36%
28.6th percentile
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | puppet | < puppet 5.4.0-1 (bullseye) | puppet 5.4.0-1 (bullseye) |
| puppet | puppet | < 5.3.4 | 5.3.4 |
| puppet | puppet | >= 0 < 5.4.0-1 | 5.4.0-1 |
| puppet | puppet | >= 0 < 4.10.10 | 4.10.10 |
| puppet | puppet | >= 0 < 3.8.5-2ubuntu0.1+esm1 | 3.8.5-2ubuntu0.1+esm1 |
| puppet | puppet | >= 1.10.0 < 1.10.10 | 1.10.10 |
| puppet | puppet | >= 5.0.0 < 5.3.4 | 5.3.4 |
| puppet | puppet_agent | — | — |
| puppet | puppet_enterprise | < 2016.4.10 | 2016.4.10 |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | >= 2017.1.0 < 2017.3.4 | 2017.3.4 |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Puppet vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 5.5
CVE-2017-10689 [MEDIUM] Puppet vulnerabilities
Title: Puppet vulnerabilities
Summary: Several security issues were fixed in Puppet.
It was discovered that Puppet installed modules with world writable
permissions. An attacker could use this vulnerability to execute arbitrary
code or cause a denial of service. (CVE-2017-10689)
It was discovered that Puppet could be used to force YAML deserialization in an
unsafe manner. A remote attacker could use this vulnerability for remote code
execution. (CVE-2017-2295)
Instructions: After a standard system update you need to restart Puppet to make
all the necessary changes.
Ubuntu
Puppet vulnerability
vendor_ubuntu·2018-02-12
CVE-2017-10689 Puppet vulnerability
Title: Puppet vulnerability
Summary: Puppet could be made to crash or run programs.
It was discovered that Puppet incorrectly handled permissions when
unpacking certain tarballs. A local user could possibly use this issue to
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
vendor_redhat·2017-08-28·CVSS 5.5
CVE-2017-10689 [MEDIUM] CWE-284 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
Statement: Red Hat Product Security has rated this issue as having security impact of Low. This issue affects the versions of puppet as shipped with:
* Red Hat Satellite 6. A future update may address this issue.
* Red Hat OpenStack Platform versions 6-12. Although the affected code is present in shipped packages, the affected code can only be exploited by deploying unsupported custom puppet modules. This issue is not currently planned to be addressed in future updates.
For additional information, refer to the Issue Severity Clas
Debian
CVE-2017-10689: puppet - In previous versions of Puppet Agent it was possible to install a module with wo...
vendor_debian·2017·CVSS 5.5
CVE-2017-10689 [MEDIUM] CVE-2017-10689: puppet - In previous versions of Puppet Agent it was possible to install a module with wo...
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
Scope: local
bullseye: resolved (fixed in 5.4.0-1)
GHSA
Tarball permission preservation in puppet
ghsa·2022-05-13
CVE-2017-10689 [MEDIUM] CWE-269 Tarball permission preservation in puppet
Tarball permission preservation in puppet
When installing a module using the system tar, the PMT will filter filesystem permissions to a sane value. This may just be based on the user's umask.
When using minitar, files are unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions.
OSV
Tarball permission preservation in puppet
osv·2022-05-13
CVE-2017-10689 [MEDIUM] Tarball permission preservation in puppet
Tarball permission preservation in puppet
When installing a module using the system tar, the PMT will filter filesystem permissions to a sane value. This may just be based on the user's umask.
When using minitar, files are unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions.
OSV
puppet vulnerabilities
osv·2021-03-15·CVSS 5.5
CVE-2017-10689 [MEDIUM] puppet vulnerabilities
puppet vulnerabilities
It was discovered that Puppet installed modules with world writable
permissions. An attacker could use this vulnerability to execute arbitrary
code or cause a denial of service. (CVE-2017-10689)
It was discovered that Puppet could be used to force YAML deserialization in an
unsafe manner. A remote attacker could use this vulnerability for remote code
execution. (CVE-2017-2295)
OSV
CVE-2017-10689: In previous versions of Puppet Agent it was possible to install a module with world writable permissions
osv·2018-02-09·CVSS 5.5
CVE-2017-10689 [MEDIUM] CVE-2017-10689: In previous versions of Puppet Agent it was possible to install a module with world writable permissions
In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
bugzilla·2018-02-07·CVSS 5.5
CVE-2017-10689 [MEDIUM] CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions
In puppet before versions 4.10.10 and 5.3.4, when unpacking tarballs with minitar in lib/puppet/module_tool/tar/mini.rb, files are unpacked with the same permissions as in the tarball allowing for files with unsafe permissions.
Upstream Advisory:
https://puppet.com/security/cve/CVE-2017-10689
Upstream Issue:
https://tickets.puppetlabs.com/browse/PUP-7866
Upstream Commit:
https://github.com/puppetlabs/puppet/commit/17d9e02da3882e44c1876e2805cf9708481715ee
Discussion:
Created puppet tracking bugs for this issue:
Affects: fedora-all [bug 1542852]
---
Please note that Puppet 3.x has mini.rb with the exact same code as 4.x, so it appears to be vulnerable, additionally the patch
Bugzilla
CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions [fedora-all]
bugzilla·2018-02-07·CVSS 5.5
CVE-2017-10689 [MEDIUM] CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions [fedora-all]
CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
2018-02-09
Published