CVE-2013-4969

Puppet <3.3.3, <3.4.1 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2013/dsa-2831
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56254
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56253
Vendor Advisory x_refsource_confirm
http://puppetlabs.com/security/cve/cve-2013-4969
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2077-1

Scores

EPSS 0.0043
EPSS Percentile 34.1%

Details

CWE
CWE-59
Status published
Products (9)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
debian/debian_linux 6.0
debian/debian_linux 7.0
debian/debian_linux 8.0
puppet/puppet_enterprise 2.0.0 - 2.8.4
puppetlabs/puppet 3.0.0 - 3.3.2
Published Jan 07, 2014
Tracked Since Feb 18, 2026