CVE-2010-0156
Publication date 3 March 2010
Last updated 24 July 2024
Ubuntu priority
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
Status
Package | Ubuntu Release | Status |
---|---|---|
puppet | ||
Patch details
Package | Patch details |
---|---|
puppet |
References
Related Ubuntu Security Notices (USN)
- USN-917-1
- Puppet vulnerabilities
- 24 March 2010