Back

MEDIUM

puppet: Puppet uses predictable filenames, allowing arbitrary file overwrite

Published May 29, 2012

Description

Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 29, 2012
Updated Aug 6, 2024
Reserved Mar 26, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date May 29, 2012
GHSA-C4MC-49HQ-Q275