CVE-2012-1989
Publication date 11 April 2012
Last updated 24 July 2024
Ubuntu priority
telnet.rb in Puppet 2.7.x before 2.7.13 and Puppet Enterprise (PE) 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows local users to overwrite arbitrary files via a symlink attack on the NET::Telnet connection log (/tmp/out.log).
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1419-1
- Puppet vulnerabilities
- 11 April 2012