CVE-2012-1906
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.
Puppet v2.6.x anterior a v2.6.15 y v2.7.x anterior a v2.7.13, y Puppet Enterprise (PE) Users v1.0, v1.1, v1.2.x, v2.0.x, y v2.5.x anterior a v2.5.1 utiliza nombres de archivos predecibles al instalar paquetes Mac OS X desde una fuente remota, permitiendo a usuarios locales sobreescribir ficheros arbitrarios o instalar paquetes arbitrarios a través de un ataque de enlace simbólico en un archivo temporal en /tmp.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-03-26 CVE Reserved
- 2012-04-11 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/52975 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74793 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://projects.puppetlabs.com/issues/13260 | 2019-07-11 | |
http://puppetlabs.com/security/cve/cve-2012-1906 | 2019-07-11 | |
http://secunia.com/advisories/48743 | 2019-07-11 | |
http://secunia.com/advisories/48748 | 2019-07-11 | |
http://secunia.com/advisories/48789 | 2019-07-11 | |
http://ubuntu.com/usn/usn-1419-1 | 2019-07-11 | |
http://www.debian.org/security/2012/dsa-2451 | 2019-07-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.0 Search vendor "Puppet" for product "Puppet" and version "2.6.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.1 Search vendor "Puppet" for product "Puppet" and version "2.6.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.2 Search vendor "Puppet" for product "Puppet" and version "2.6.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.3 Search vendor "Puppet" for product "Puppet" and version "2.6.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.4 Search vendor "Puppet" for product "Puppet" and version "2.6.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.5 Search vendor "Puppet" for product "Puppet" and version "2.6.5" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.6 Search vendor "Puppet" for product "Puppet" and version "2.6.6" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.7 Search vendor "Puppet" for product "Puppet" and version "2.6.7" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.8 Search vendor "Puppet" for product "Puppet" and version "2.6.8" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.9 Search vendor "Puppet" for product "Puppet" and version "2.6.9" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.10 Search vendor "Puppet" for product "Puppet" and version "2.6.10" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.11 Search vendor "Puppet" for product "Puppet" and version "2.6.11" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.12 Search vendor "Puppet" for product "Puppet" and version "2.6.12" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.13 Search vendor "Puppet" for product "Puppet" and version "2.6.13" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.6.14 Search vendor "Puppet" for product "Puppet" and version "2.6.14" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.2 Search vendor "Puppet" for product "Puppet" and version "2.7.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.3 Search vendor "Puppet" for product "Puppet" and version "2.7.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.4 Search vendor "Puppet" for product "Puppet" and version "2.7.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.5 Search vendor "Puppet" for product "Puppet" and version "2.7.5" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.6 Search vendor "Puppet" for product "Puppet" and version "2.7.6" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.7 Search vendor "Puppet" for product "Puppet" and version "2.7.7" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.8 Search vendor "Puppet" for product "Puppet" and version "2.7.8" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.9 Search vendor "Puppet" for product "Puppet" and version "2.7.9" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.10 Search vendor "Puppet" for product "Puppet" and version "2.7.10" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2.7.11 Search vendor "Puppet" for product "Puppet" and version "2.7.11" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.5.0 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.5.0" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Search vendor "Puppetlabs" for product "Puppet" | 2.7.0 Search vendor "Puppetlabs" for product "Puppet" and version "2.7.0" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Search vendor "Puppetlabs" for product "Puppet" | 2.7.1 Search vendor "Puppetlabs" for product "Puppet" and version "2.7.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.0 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.1 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.2 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.2" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.3 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.3" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 1.2.4 Search vendor "Puppet" for product "Puppet Enterprise" and version "1.2.4" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.0 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.1 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.1" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Enterprise Search vendor "Puppet" for product "Puppet Enterprise" | 2.0.2 Search vendor "Puppet" for product "Puppet Enterprise" and version "2.0.2" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Enterprise Users Search vendor "Puppetlabs" for product "Puppet Enterprise Users" | 1.0 Search vendor "Puppetlabs" for product "Puppet Enterprise Users" and version "1.0" | - |
Affected
| ||||||
Puppetlabs Search vendor "Puppetlabs" | Puppet Enterprise Users Search vendor "Puppetlabs" for product "Puppet Enterprise Users" | 1.1 Search vendor "Puppetlabs" for product "Puppet Enterprise Users" and version "1.1" | - |
Affected
|