CVE-2012-1906: Low severity puppet vulnerability
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1906?
CVE-2012-1906 is classified as a moderate vulnerability due to the potential for local users to overwrite arbitrary files or install unwanted packages.
How do I fix CVE-2012-1906?
To mitigate CVE-2012-1906, upgrade Puppet to version 2.6.15 or later for 2.6.x installations, or to version 2.7.13 or later for 2.7.x installations.
Which versions of Puppet are affected by CVE-2012-1906?
Puppet versions 2.6.x before 2.6.15 and 2.7.x before 2.7.13, along with specific Puppet Enterprise user versions, are affected by CVE-2012-1906.
What type of attack is CVE-2012-1906 associated with?
CVE-2012-1906 allows local users to perform file overwriting and arbitrary package installation, which can lead to privilege escalation.
Is CVE-2012-1906 relevant for Mac OS X users?
Yes, CVE-2012-1906 particularly affects Mac OS X packages installed from remote sources, making it relevant for Mac OS X users using vulnerable Puppet versions.