CVE-2013-4956

NameCVE-2013-4956
DescriptionPuppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally built, which might allow local users to read or modify those modules depending on the original permissions.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2761-1
NVD severitylow (attack range: local)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
puppet (PTS)squeeze (security), squeeze2.6.2-5+squeeze9fixed
squeeze (lts)2.6.2-5+squeeze10fixed
wheezy, wheezy (security)2.7.23-1~deb7u3fixed
jessie, sid3.7.2-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
puppetsource(unstable)3.2.4-1low
puppetsourcesqueeze(not affected)
puppetsourcewheezy2.7.23-1~deb7u1lowDSA-2761-1

Notes

[squeeze] - puppet <not-affected> (puppet module not yet present)

Search for package or bug name: Reporting problems