CVE-2012-1906

Puppet 2.6.x < 2.6.15, 2.7.x < 2.7.13, Puppet Enterprise < 2.5.1 - Arbitrary File Write via Symlink Attack

Title source: llm
STIX 2.1

Description

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.

References (9)

Core 9
Core References
Vendor Advisory x_refsource_misc
http://projects.puppetlabs.com/issues/13260
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-1419-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48743
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74793
Vendor Advisory x_refsource_confirm
http://puppetlabs.com/security/cve/cve-2012-1906/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52975
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48748
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2451
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48789

Scores

EPSS 0.0006
EPSS Percentile 19.7%

Details

CWE
CWE-264
Status published
Products (39)
puppet/puppet 2.6.0
puppet/puppet 2.6.1
puppet/puppet 2.6.2
puppet/puppet 2.6.3
puppet/puppet 2.6.4
puppet/puppet 2.6.5
puppet/puppet 2.6.6
puppet/puppet 2.6.7
puppet/puppet 2.6.8
puppet/puppet 2.6.9
... and 29 more
Published May 29, 2012
Tracked Since Feb 18, 2026