Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2011-3872

Published: 24 October 2011

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

Priority

High

Status

Package Release Status
puppet
Launchpad, Ubuntu, Debian
hardy Ignored
(end of life)
lucid
Released (0.25.4-2ubuntu6.5)
maverick
Released (2.6.1-0ubuntu2.4)
natty
Released (2.6.4-2ubuntu2.5)
oneiric
Released (2.7.1-1ubuntu3.2)
upstream
Released (2.7.6)