---
title: "CVE-2013-1654\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1654?format=md
keywords: index, follow
---

# CVE-2013-1654

Publication date 12 March 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise
2.7.x before 2.7.2, does not properly negotiate the SSL protocol between
client and master, which allows remote attackers to conduct SSLv2 downgrade
attacks against SSLv3 sessions via unspecified vectors.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1654?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| puppet | 12.10 quantal | Fixed 2.7.18-1ubuntu1.1 |
| 12.04 LTS precise | Fixed 2.7.11-1ubuntu2.2 |
| 11.10 oneiric | Fixed 2.7.1-1ubuntu3.8 |
| 10.04 LTS lucid | Ignored |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

Upstream no longer supports 0.25.x as found in lucid. The code
is substantially different, rendering a backport of this
security update difficult. Since puppet in Lucid is almost
end-of-life, we aren't planning on backporting the security fix
to it. For Lucid users, we recommend using puppet
2.7.1-1ubuntu3.8~ubuntu10.04.1 currently in lucid-backports.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1654)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1654)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1654)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1654)

### Related Ubuntu Security Notices (USN)

+ [USN-1759-1](https://usn.ubuntu.com/USN-1759-1)
+ Puppet vulnerabilities
+ 12 March 2013

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2013-1654>
