[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-1053Date: (C)2012-05-29   (M)2024-02-09


The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-48157
SECUNIA-48161
SECUNIA-48166
SECUNIA-48290
BID-52158
OSVDB-79495
DSA-2419
SUSE-SU-2012:0325
USN-1372-1
http://projects.puppetlabs.com/issues/12457
http://projects.puppetlabs.com/issues/12458
http://projects.puppetlabs.com/issues/12459
http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14
http://puppetlabs.com/security/cve/cve-2012-1053/
openSUSE-SU-2012:0835
puppet-forked-priv-escalation(73445)

CPE    2
cpe:/a:puppetlabs:puppet:2.7.1
cpe:/a:puppetlabs:puppet:2.7.0
CWE    1
CWE-264
OVAL    11
oval:org.secpod.oval:def:1601258
oval:org.secpod.oval:def:700779
oval:org.secpod.oval:def:5917
oval:org.secpod.oval:def:6022
...

© SecPod Technologies