LWN.net Logo

puppet: code execution

Package(s):puppet CVE #(s):CVE-2013-3567
Created:June 19, 2013 Updated:August 22, 2013
Description: From the Ubuntu advisory:

It was discovered that Puppet incorrectly handled YAML payloads. An attacker on an untrusted client could use this issue to execute arbitrary code on the master.

Alerts:
Ubuntu USN-1886-1 2013-06-18
Debian DSA-2715-1 2013-06-26
Mageia MGASA-2013-0187 2013-06-26
Mandriva MDVSA-2013:186 2013-06-28
SUSE SUSE-SU-2013:1304-1 2013-08-06
openSUSE openSUSE-SU-2013:1370-1 2013-08-22
Gentoo 201308-04 2013-08-23
Red Hat RHSA-2013:1283-01 2013-09-24
Red Hat RHSA-2013:1284-01 2013-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds