Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-0528

Published: 31 January 2011

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the resources of other nodes via unspecified vectors.

Notes

AuthorNote
jdstrand
per upstream, puppet prior to 2.6.0 not affected
improper merges from Debian uncommitted the upstream fixes for
this in 11.04 and 11.10.

Priority

Medium

Status

Package Release Status
puppet
Launchpad, Ubuntu, Debian
hardy Not vulnerable

lucid Not vulnerable
(0.25.4-2ubuntu6.5)
maverick
Released (2.6.1-0ubuntu2.5)
natty
Released (2.6.4-2ubuntu2.7)
oneiric
Released (2.7.1-1ubuntu3.4)
upstream
Released (2.6.2-3)