---
title: "CVE-2012-1986\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-1986?format=md
keywords: index, follow
---

# CVE-2012-1986

Publication date 11 April 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise
(PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote
authenticated users with an authorized SSL key and certain permissions on
the puppet master to read arbitrary files via a symlink attack in
conjunction with a crafted REST request for a file in a filebucket.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| puppet | 11.10 oneiric | Fixed 2.7.1-1ubuntu3.6 |
| 11.04 natty | Fixed 2.6.4-2ubuntu2.9 |
| 10.10 maverick | Ignored end of life |
| 10.04 LTS lucid | Fixed 0.25.4-2ubuntu6.7 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1986)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-1986)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-1986)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-1986)

### Related Ubuntu Security Notices (USN)

+ [USN-1419-1](https://usn.ubuntu.com/USN-1419-1)
+ Puppet vulnerabilities
+ 11 April 2012

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2012-1986>
