Puppet CVE-2013-3567 Remote Code Execution Vulnerability
BID:60664
Info
Puppet CVE-2013-3567 Remote Code Execution Vulnerability
| Bugtraq ID: | 60664 |
| Class: | Unknown |
| CVE: |
CVE-2013-3567 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2013 12:00AM |
| Updated: | Mar 19 2015 09:44AM |
| Credit: | Ben Murphy |
| Vulnerable: |
Puppet Labs Puppet Enterprise 2.5.1 Puppet Labs Puppet Enterprise 2.0.3 Puppet Labs Puppet Enterprise 2.0.2 Puppet Labs Puppet Enterprise 2.6 Puppet Labs Puppet Enterprise 2.0 Puppet Labs Puppet 2.7.13 Puppet Labs Puppet 2.7.11 Puppet Labs Puppet 2.7.10 Puppet Labs Puppet 2.7.5 Puppet Labs Puppet 2.7.4 Puppet Labs Puppet 2.6.15 Puppet Labs Puppet 2.6.14 Puppet Labs Puppet 2.6.13 Puppet Labs Puppet 2.6.11 Puppet Labs Puppet 2.6.10 Puppet Labs Puppet 2.6.4 Puppet Labs Puppet 2.6.3 Puppet Labs Puppet 2.6 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Puppet CVE-2013-3567 Remote Code Execution Vulnerability
Puppet is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
The issue is fixed in Puppet versions 2.7.22 and 3.2.2, and Puppet Enterprise 2.8.2.
Puppet is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the application.
The issue is fixed in Puppet versions 2.7.22 and 3.2.2, and Puppet Enterprise 2.8.2.
Exploit / POC
Puppet CVE-2013-3567 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: \"mailto:[email protected]\".
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: \"mailto:[email protected]\".
Solution / Fix
Puppet CVE-2013-3567 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Puppet CVE-2013-3567 Remote Code Execution Vulnerability
References:
References:
- Bug 974649 - (CVE-2013-3567) CVE-2013-3567 puppet: remote code execution on mast (Red Hat)
- Puppet Homepage (Puppet Labs)
- CVE-2013-3567 (Unauthenticated Remote Code Execution Vulnerability) (Puppet Labs)
- Security Advisory Critical: ruby193-puppet security update (Red Hat)
- Security Advisory Moderate: puppet security update (Red Hat)