---
title: "CVE-2012-3865\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-3865?format=md
keywords: index, follow
---

# CVE-2012-3865

Publication date 12 July 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet
before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2,
when Delete is enabled in auth.conf, allows remote authenticated users to
delete arbitrary files on the puppet master server via a .. (dot dot) in a
node name.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| puppet | 12.04 LTS precise | Fixed 2.7.11-1ubuntu2.1 |
| 11.10 oneiric | Fixed 2.7.1-1ubuntu3.7 |
| 11.04 natty | Fixed 2.6.4-2ubuntu2.10 |
| 10.04 LTS lucid | Fixed 0.25.4-2ubuntu6.8 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3865)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-3865)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-3865)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-3865)

### Related Ubuntu Security Notices (USN)

+ [USN-1506-1](https://usn.ubuntu.com/USN-1506-1)
+ Puppet vulnerabilities
+ 12 July 2012

### Other references

* <http://puppetlabs.com/security/cve/cve-2012-3865/>
* <https://www.cve.org/CVERecord?id=CVE-2012-3865>
