oss-sec mailing list archives

Re: Fwd: New Security Vulnerabilities in Puppet


From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 11 Jul 2012 12:04:50 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 07/11/2012 10:37 AM, Moses Mendoza wrote:

Vulnerability 5 Agents with certnames of IP addresses can be 
impersonated (low) *Affected Versions: 2.7.x, 2.6.x If an 
authenticated host with a certname of an IP address changes IP 
addresses, and a second host assumes the first host's former
IP address, the second host will be treated by the puppet
master as the first one, giving the second host access to the
first host's catalog. Note: This will not be fixed in Puppet
versions prior to the forthcoming 3.x. Instead, with this
announcement IP-based authentication in Puppet < 3.x is
deprecated.

After some further communications with them it has been decided to
assign this issue a CVE. Please use CVE-2012-3408 for this issue.

Moses: can you confirm that a CVE page with links to the code
commits/etc will be created? Thanks.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJP/cBCAAoJEBYNRVNeJnmTy20P/RSOFcMm17lRy6ZYGZNBeXxp
AD/yyljK4eAIGOG7Nvbx9AIce1BRbb+MdxJbRqFtVhO26bRgiCGViM6I0o6lyEKH
Wh0HeLls5YtgxcNquhyJsvQQOaZ8uWRa7j09Pzm6YL0076rTxS0o7jPIt0dudRSe
u3IfbsxRWPaiurDw9XhkhxuZYGpdRf6c0XR0aHtbFwnt5Huwjf8p8GnyP16rwQcR
csr+IcWixMNZULIqh1+NoUG1uJiWYfK7LZ54q3Bm3yVWRBLzqOzao1pa9jWJwAxy
9saqOwP3TKbpDh43QcLaiT88taK71vcyezhvIlZH2LwPKk0eQSYfXAw65/bTaKIv
iCBcYgeasV5/xPYXBVglAuwqYbd1CEJTKZGenYGAPdxxrm63HIlzFeWJnL02sQZe
+6g0AVGJ6J6bHPI7TgEZsMXrEo8rfrKtAOYlDp5YsMC0YQQX4wovFbhJi0EcTeu0
uOS80adyvVDgHxdE6A3SOq3+458aCuiQ4rkp1Tf0Au/20u0zFGaytMITnJGmmFfB
NPrSNQvknuK8C/t4C7MS4lTAJu1CvTjWzeeAxgLRPb9zyEgdkEiu0yTdUH8twG5O
xfG3c0sp0jOmaKGDblTNKvMxicKppbBp2ZBmT0NbBLTG02NDCucTtOQfWizYWmDB
It5g13Hj2PmBbNOuWifm
=CbYi
-----END PGP SIGNATURE-----


Current thread: