CVE-2012-1053: Medium severity Puppet Puppet vulnerability
The changeuser method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the changeuser not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1053?
CVE-2012-1053 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2012-1053?
To fix CVE-2012-1053, upgrade Puppet to version 2.6.14 or 2.7.11 or later.
Which versions are affected by CVE-2012-1053?
CVE-2012-1053 affects Puppet versions 2.6.x before 2.6.14 and 2.7.x before 2.7.11, as well as specific Puppet Enterprise Users versions.
Who can exploit CVE-2012-1053?
Local users can exploit CVE-2012-1053 to gain elevated privileges due to improper group privilege management.
Is there a patch for CVE-2012-1053?
Yes, the patch for CVE-2012-1053 is included in the updated versions of Puppet since 2.6.14 and 2.7.11.