CVE-2012-1989: Low severity puppet vulnerability
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Other sources
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1989?
CVE-2012-1989 is classified with a moderate severity level due to the potential for local users to exploit the symlink attack.
How do I fix CVE-2012-1989?
To fix CVE-2012-1989, update Puppet to version 2.7.13 or later.
Which versions of Puppet are affected by CVE-2012-1989?
Puppet versions 2.7.x before 2.7.13 and Puppet Enterprise versions 1.2.x, 2.0.x, and 2.5.x before 2.5.1 are affected by CVE-2012-1989.
What is the nature of the vulnerability in CVE-2012-1989?
The vulnerability allows local users to overwrite arbitrary files through a symlink attack on the NET::Telnet connection log.
Is CVE-2012-1989 a remote or local vulnerability?
CVE-2012-1989 is a local vulnerability that requires user access to exploit.