Description
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
References (5)
Core 5
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2013/dsa-2831
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56254
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56253
Vendor Advisory x_refsource_confirm
http://puppetlabs.com/security/cve/cve-2013-4969
Third Party Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2077-1
Scores
EPSS
0.0043
EPSS Percentile
34.1%
Details
CWE
CWE-59
Status
published
Products (9)
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
12.10
canonical/ubuntu_linux
13.04
canonical/ubuntu_linux
13.10
debian/debian_linux
6.0
debian/debian_linux
7.0
debian/debian_linux
8.0
puppet/puppet_enterprise
2.0.0 - 2.8.4
puppetlabs/puppet
3.0.0 - 3.3.2
Published
Jan 07, 2014
Tracked Since
Feb 18, 2026