Описание
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Отчет
Red Hat Product Security has rated this issue as having Low security impact in Subscription Asset Manager 1. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | puppet | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | puppet | Not affected | ||
| Red Hat Enterprise MRG 1 | puppet | Will not fix | ||
| Red Hat OpenStack Platform 3 | puppet | Will not fix | ||
| Red Hat OpenStack Platform 3 | ruby193-puppet | Will not fix | ||
| Red Hat OpenStack Platform 4 | puppet | Affected | ||
| Red Hat Satellite 6 | ruby193-puppet | Affected | ||
| Red Hat Subscription Asset Manager | puppet | Will not fix |
Показывать по
Дополнительная информация
Статус:
2.1 Low
CVSS2
Связанные уязвимости
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) be ...
Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.
2.1 Low
CVSS2