Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6508

Опубликовано: 09 фев. 2018
Источник: debian
EPSS Низкий

Описание

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
puppet-module-puppetlabs-aptfixed4.5.1-1package
puppet-module-puppetlabs-apachefixed3.0.0-1package
puppet-module-puppetlabs-mysqlfixed5.3.0-1package

Примечания

  • https://puppet.com/security/cve/CVE-2018-6508

  • Issue in various puppet modules: facter_task, puppet_conf, apt, apache and mysql modules

  • https://github.com/puppetlabs/puppetlabs-facter_task/commit/dd37c72e78c8a37e671e20becb05d6ceafdbd81c

  • https://github.com/puppetlabs/puppetlabs-puppet_conf/commit/ba434605717e16d935cba45ab38ca5866780a36b

  • https://github.com/puppetlabs/puppetlabs-apt/commit/81879be960d5723016e3d0b4ff155ee704261bbc

  • https://github.com/puppetlabs/puppetlabs-apache/commit/81bc5119ceced1faa4bf261efa4b7cd3731ef3ef

  • https://github.com/puppetlabs/puppetlabs-mysql/commit/da3684c79d5fe6ece826e087e8693c75ac40414c

  • This is only exploitable with Puppet Tasks, which aren't packaged/available in Debian

EPSS

Процентиль: 75%
0.00905
Низкий

Связанные уязвимости

CVSS3: 8
ubuntu
почти 8 лет назад

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

CVSS3: 9
redhat
около 8 лет назад

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

CVSS3: 8
nvd
почти 8 лет назад

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

CVSS3: 8
github
больше 3 лет назад

Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.

EPSS

Процентиль: 75%
0.00905
Низкий