ADVISORIES
GEM
SEVERITY
CVSS v2.0: 3.6 (Low)
UNAFFECTED VERSIONS
- < 2.7.1
PATCHED VERSIONS
- ~> 2.5.1
- >= 2.7.13
DESCRIPTION
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
RELATED
- https://nvd.nist.gov/vuln/detail/CVE-2012-1989
- https://www.puppet.com/security/cve/cve-2012-1989-arbitrary-file-write-access
- https://github.com/advisories/GHSA-c5qq-g673-5p49
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74797
- https://security.gentoo.org/glsa/201208-02
- http://ubuntu.com/usn/usn-1419-1
- http://lists.opensuse.org/opensuse-updates/2012-05/msg00012.html
- https://web.archive.org/web/20210121211512/http://www.securityfocus.com/bid/52975
- https://web.archive.org/web/20111225083933/http://secunia.com/advisories/49136
- https://web.archive.org/web/20111225083933/http://secunia.com/advisories/48748
- https://web.archive.org/web/20121025194938/http://secunia.com/advisories/48743