First published: Mon Dec 08 2008(Updated: )
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/0.24.8 | <4.el4 | 4.el4 |
Puppet | =0.24.6 | |
CentOS CentOS | ||
Fedoraproject Fedora | ||
All of | ||
Puppet | =0.24.6 | |
Fedora |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3564 has a moderate severity rating due to the potential for local users to access restricted files.
To fix CVE-2009-3564, upgrade Puppet to version 0.24.8 or later.
CVE-2009-3564 affects Puppet version 0.24.6 specifically.
There are no documented workarounds for CVE-2009-3564; upgrading is recommended.
Local users on systems running Puppet 0.24.6 may be impacted by CVE-2009-3564.