---
title: "CVE-2012-1053\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-1053?format=md
keywords: index, follow
---

# CVE-2012-1053

Publication date 23 February 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The change\_user method in the SUIDManager (lib/puppet/util/suidmanager.rb)
in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet
Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly
manage group privileges, which allows local users to gain privileges via
vectors related to (1) the change\_user not dropping supplementary groups in
certain conditions, (2) changes to the eguid without associated changes to
the egid, or (3) the addition of the real gid to supplementary groups.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| puppet | 11.10 oneiric | Fixed 2.7.1-1ubuntu3.5 |
| 11.04 natty | Fixed 2.6.4-2ubuntu2.8 |
| 10.10 maverick | Fixed 2.6.1-0ubuntu2.6 |
| 10.04 LTS lucid | Fixed 0.25.4-2ubuntu6.6 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1053)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-1053)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-1053)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-1053)

### Related Ubuntu Security Notices (USN)

+ [USN-1372-1](https://usn.ubuntu.com/USN-1372-1)
+ Puppet vulnerabilities
+ 23 February 2012

### Other references

* <http://puppetlabs.com/security/cve/cve-2012-1053/>
* <https://www.cve.org/CVERecord?id=CVE-2012-1053>
