CVE-2012-1053
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
El método change_user en el SUIDManager SUIDManager (lib/puppet/util/suidmanager.rb) en Puppet v2.6.x anterior a v2.6.14 y v2.7.x anterior a v2.7.11, y Puppet Enterprise (PE) Users v1.0, v1.1, v1.2.x, v2.0.x anterior a 2.0.3 no gestiona adecuadamente los privilegios de grupo, lo que permite a usuarios locales conseguir privilegios a través de vectores relacionados con (1) change_user en ciertas condiciones, (2) cambios en el eguid sin cambios asociados a la egid, o (3) la adición de la gid real a grupos complementarios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-13 CVE Reserved
- 2012-02-24 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://projects.puppetlabs.com/issues/12457 | X_refsource_misc | |
http://projects.puppetlabs.com/issues/12458 | X_refsource_misc | |
http://projects.puppetlabs.com/issues/12459 | X_refsource_misc | |
http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14 | X_refsource_confirm | |
http://secunia.com/advisories/48157 | Third Party Advisory | |
http://www.osvdb.org/79495 | Vdb Entry | |
http://www.securityfocus.com/bid/52158 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/73445 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.html | 2019-07-11 | |
http://puppetlabs.com/security/cve/cve-2012-1053 | 2019-07-11 | |
http://secunia.com/advisories/48161 | 2019-07-11 | |
http://secunia.com/advisories/48166 | 2019-07-11 | |
http://secunia.com/advisories/48290 | 2019-07-11 | |
http://ubuntu.com/usn/usn-1372-1 | 2019-07-11 | |
http://www.debian.org/security/2012/dsa-2419 | 2019-07-11 | |
https://hermes.opensuse.org/messages/15087408 | 2019-07-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.0 Search vendor "Puppet" for product "Puppet" and version "2.6.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.1 Search vendor "Puppet" for product "Puppet" and version "2.6.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.2 Search vendor "Puppet" for product "Puppet" and version "2.6.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.3 Search vendor "Puppet" for product "Puppet" and version "2.6.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.4 Search vendor "Puppet" for product "Puppet" and version "2.6.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.5 Search vendor "Puppet" for product "Puppet" and version "2.6.5" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.6 Search vendor "Puppet" for product "Puppet" and version "2.6.6" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.7 Search vendor "Puppet" for product "Puppet" and version "2.6.7" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.8 Search vendor "Puppet" for product "Puppet" and version "2.6.8" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.9 Search vendor "Puppet" for product "Puppet" and version "2.6.9" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.10 Search vendor "Puppet" for product "Puppet" and version "2.6.10" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.11 Search vendor "Puppet" for product "Puppet" and version "2.6.11" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.12 Search vendor "Puppet" for product "Puppet" and version "2.6.12" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.13 Search vendor "Puppet" for product "Puppet" and version "2.6.13" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.2 Search vendor "Puppet" for product "Puppet" and version "2.7.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.3 Search vendor "Puppet" for product "Puppet" and version "2.7.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.4 Search vendor "Puppet" for product "Puppet" and version "2.7.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.5 Search vendor "Puppet" for product "Puppet" and version "2.7.5" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.6 Search vendor "Puppet" for product "Puppet" and version "2.7.6" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.7 Search vendor "Puppet" for product "Puppet" and version "2.7.7" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.8 Search vendor "Puppet" for product "Puppet" and version "2.7.8" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.9 Search vendor "Puppet" for product "Puppet" and version "2.7.9" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.10 Search vendor "Puppet" for product "Puppet" and version "2.7.10" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Search vendor "Puppetlabs" for product "Puppet" | 2.7.0 Search vendor "Puppetlabs" for product "Puppet" and version "2.7.0" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Search vendor "Puppetlabs" for product "Puppet" | 2.7.1 Search vendor "Puppetlabs" for product "Puppet" and version "2.7.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.0 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.1 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.2 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.3 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.4 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.0 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.1 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.2 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.2" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Enterprise Users Search vendor "Puppetlabs" for product "Puppet Enterprise Users" | 1.0 Search vendor "Puppetlabs" for product "Puppet Enterprise Users" and version "1.0" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Enterprise Users Search vendor "Puppetlabs" for product "Puppet Enterprise Users" | 1.1 Search vendor "Puppetlabs" for product "Puppet Enterprise Users" and version "1.1" | - |
Affected
|