| Name | CVE-2013-4969 |
| Description | Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-2831-1 |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| puppet | source | squeeze | 2.6.2-5+squeeze9 | DSA-2831-1 | ||
| puppet | source | wheezy | 2.7.23-1~deb7u2 | DSA-2831-1 | ||
| puppet | source | (unstable) | 3.4.1-1 |
http://puppetlabs.com/security/cve/cve-2013-4969