Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | |||
CVE ID: | CVE-2014-3248 |
Description: | Untrusted search path vulnerability in Puppet Enterprise 2.8 before 2.8.7, Puppet before 2.7.26 and 3.x before 3.6.2, Facter 1.6.x and 2.x before 2.0.2, Hiera before 1.3.4, and Mcollective before 2.5.2, when running with Ruby 1.9.1 or earlier, allows local users to gain privileges via a Trojan horse file in the current working directory, as demonstrated using (1) rubygems/defaults/operating_system.rb, (2) Win32API.rb, (3) Win32API.so, (4) safe_yaml.rb, (5) safe_yaml/deep.rb, or (6) safe_yaml/deep.so; or (7) operatingsystem.rb, (8) operatingsystem.so, (9) osfamily.rb, or (10) osfamily.so in puppet/confine. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.868513 1.3.6.1.4.1.25623.1.0.120328 1.3.6.1.4.1.25623.1.0.120013 1.3.6.1.4.1.25623.1.0.121331 1.3.6.1.4.1.25623.1.1.4.2014.0880.1 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-3248 BugTraq ID: 68035 http://www.securityfocus.com/bid/68035 http://rowediness.com/2014/06/13/cve-2014-3248-a-little-problem-with-puppet/ http://secunia.com/advisories/59197 http://secunia.com/advisories/59200 |