GLSA-201308-04 : Puppet: Multiple vulnerabilities

high Nessus Plugin ID 69464

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-201308-04 (Puppet: Multiple vulnerabilities)

Multiple vulnerabilities have been discovered in Puppet. Please review the CVE identifiers referenced below for details.
Impact :

A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, obtain sensitive information, or bypass security restrictions.
Workaround :

There is no known workaround at this time.

Solution

All Puppet users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=app-admin/puppet-2.7.23'

See Also

https://security.gentoo.org/glsa/201308-04

Plugin Details

Severity: High

ID: 69464

File Name: gentoo_GLSA-201308-04.nasl

Version: 1.10

Type: local

Published: 8/25/2013

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:puppet, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/23/2013

Reference Information

CVE: CVE-2012-6120, CVE-2013-1640, CVE-2013-1652, CVE-2013-1653, CVE-2013-1654, CVE-2013-1655, CVE-2013-2274, CVE-2013-2275, CVE-2013-3567, CVE-2013-4761, CVE-2013-4956

BID: 58442, 58443, 58446, 58447, 58449, 58452, 58453, 58887, 60664, 61805, 61806

GLSA: 201308-04