CVE-2013-4969: Low severity puppet vulnerability
Published Jan 7, 2014
·Updated
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Affected Software
11 affected components
Puppetlabs Puppet>=3.0.0<=3.3.2
Puppetlabs Puppet>=3.4.0<3.4.1
Puppet Puppet Enterprise>=2.0.0<2.8.4
Puppet Puppet Enterprise>=3.1<3.1.1
Debian Debian Linux=6.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.04
Canonical Ubuntu Linux=13.10
Event History
Jan 7, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4969?
CVE-2013-4969 has a moderate severity due to the potential for local users to exploit symlink attacks.
2
How do I fix CVE-2013-4969?
To fix CVE-2013-4969, upgrade Puppet to version 3.3.3 or later, or 3.4.1 or later for 3.4.x versions.
3
Which versions of Puppet are affected by CVE-2013-4969?
Puppet versions before 3.3.3, 3.4 before 3.4.1, Puppet Enterprise before 2.8.4, and 3.1 before 3.1.1 are affected by CVE-2013-4969.
4
Is CVE-2013-4969 a remote vulnerability?
No, CVE-2013-4969 is a local vulnerability allowing exploitation by local users only.
5
What types of systems are impacted by CVE-2013-4969?
CVE-2013-4969 impacts systems running affected versions of Puppet or Puppet Enterprise on various Linux distributions.