telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2012-06-27 11:55
Updated : 2019-07-11 08:09
NVD link : CVE-2012-1989
Mitre link : CVE-2012-1989
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
puppet
- puppet_enterprise
- puppet
puppetlabs
- puppet