| From: |
| updates@fedoraproject.org |
| To: |
| package-announce@lists.fedoraproject.org |
| Subject: |
| [SECURITY] Fedora 15 Update: puppet-2.6.12-1.fc15 |
| Date: |
| Sat, 19 Nov 2011 06:01:24 +0000 |
| Message-ID: |
| <20111119060125.6EB1C20F73@bastion01.phx2.fedoraproject.org> |
| Archive-link: |
| Article, Thread
|
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-14994
2011-10-27 03:28:55
--------------------------------------------------------------------------------
Name : puppet
Product : Fedora 15
Version : 2.6.12
Release : 1.fc15
URL : http://puppetlabs.com
Summary : A network tool for managing many disparate systems
Description :
Puppet lets you centrally manage every important aspect of your system using a
cross-platform specification language that manages all the separate elements
normally aggregated in different files, like users, cron jobs, and hosts,
along with obviously discrete elements like packages, services, and files.
--------------------------------------------------------------------------------
Update Information:
A bug in puppet's SSL certificate handling could allow nodes with a valid certificate to
impersonate the puppet master. To be vulnerable, a user would have had to set the certdnsnames
variable and generated certificates. This setting is not set by default in the Fedora/EPEL
packages.
This update closes the vulnerability in newly generated certificates, but cannot prevent existing
certificates from being used to exploit the vulnerability. Please refer to the upstream
documentation for more details on mitigation and remediation of this issue, if you have generate
certificates that are vulnerable to this issue:
http://puppetlabs.com/security/cve/cve-2011-3872/
--------------------------------------------------------------------------------
ChangeLog:
* Sun Oct 23 2011 Todd Zullinger <tmz@pobox.com> - 2.6.12-1
- Update to 2.6.12, fixes CVE-2011-3872
- Add upstream patch to restore Mongrel XMLRPC functionality (upstream #10244)
- Apply partial fix for upstream #9167 (tagmail report sends email when nothing
happens)
* Thu Sep 29 2011 Todd Zullinger <tmz@pobox.com> - 2.6.6-3
- Apply upstream patches for CVE-2011-3869, CVE-2011-3870, CVE-2011-3871, and
upstream #9793
* Tue Sep 27 2011 Todd Zullinger <tmz@pobox.com> - 2.6.6-2
- Apply upstream patch for CVE-2011-3848
* Wed Mar 16 2011 Todd Zullinger <tmz@pobox.com> - 2.6.6-1
- Update to 2.6.6
- Ensure %pre exits cleanly
- Fix License tag, puppet is now GPLv2 only
- Create and own /usr/share/puppet/modules (#615432)
- Properly restart puppet agent/master daemons on upgrades from 0.25.x
- Require libselinux-utils when selinux support is enabled
- Support tmpfiles.d for Fedora >= 15 (#656677)
- Apply a few upstream fixes for 0.25.5 regressions
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update puppet' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-...
(
Log in to post comments)