CVE-2014-7170: Race Condition
Published Dec 17, 2014
·Updated
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.
Affected Software
1 affected component
Puppet Puppet Server=0.2.0
Event History
Dec 17, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7170?
CVE-2014-7170 has a medium severity rating due to the potential for local users to access sensitive information.
2
How do I fix CVE-2014-7170?
To fix CVE-2014-7170, upgrade Puppet Server to a version higher than 0.2.0.
3
What systems are affected by CVE-2014-7170?
CVE-2014-7170 specifically affects Puppet Server version 0.2.0.
4
What type of vulnerability is CVE-2014-7170?
CVE-2014-7170 is classified as a race condition vulnerability.
5
Can CVE-2014-7170 be exploited remotely?
CVE-2014-7170 is a local vulnerability, meaning it can only be exploited by users with local access to the system.