Security update for puppet
SUSE Security Update: Security update for puppet
This update fixes the following issues:
* CVE-2011-1986: Filebucket arbitrary file read
* CVE-2012-1987: Filebucket DoS
* CVE-2012-1988: Filebucket arbitrary code execution
* CVE-2012-1989: insecure handling of temporary files
Security Issue references:
* CVE-2012-1988
>
* CVE-2012-1989
>
* CVE-2012-1986
>
* CVE-2012-1987
>
http://support.novell.com/security/cve/CVE-2012-1986.html
http://support.novell.com/security/cve/CVE-2012-1987.html
http://support.novell.com/security/cve/CVE-2012-1988.html
http://support.novell.com/security/cve/CVE-2012-1989.html
https://bugzilla.novell.com/755726
https://bugzilla.novell.com/755869
https://bugzilla.novell.com/755870
https://bugzilla.novell.com/755871
https://bugzilla.novell.com/755872
http://download.suse.com/patch/finder/?keywords=d5875dc9c1e3b6b7298be6f4723c1894
Announcement ID: | SUSE-SU-2012:0771-1 |
Rating: | moderate |
References: | #755726 #755869 #755870 #755871 #755872 |
Affected Products: |
An update that solves four vulnerabilities and has one errata is now available. It includes one version update.
Description:
This update fixes the following issues:
* CVE-2011-1986: Filebucket arbitrary file read
* CVE-2012-1987: Filebucket DoS
* CVE-2012-1988: Filebucket arbitrary code execution
* CVE-2012-1989: insecure handling of temporary files
Security Issue references:
* CVE-2012-1988
* CVE-2012-1989
* CVE-2012-1986
* CVE-2012-1987
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Server 11 SP2:
zypper in -t patch slessp1-puppet-6115
- SUSE Linux Enterprise Server 11 SP1 for VMware:
zypper in -t patch slessp1-puppet-6115
- SUSE Linux Enterprise Server 11 SP1:
zypper in -t patch slessp1-puppet-6115
- SUSE Linux Enterprise Desktop 11 SP2:
zypper in -t patch sledsp1-puppet-6115
- SUSE Linux Enterprise Desktop 11 SP1:
zypper in -t patch sledsp1-puppet-6115
To bring your system up-to-date, use "zypper patch".
Package List:
- SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64) [New Version: 2.6.12]:
- puppet-2.6.12-0.14.1
- puppet-server-2.6.12-0.14.1
- SUSE Linux Enterprise Server 11 SP1 for VMware (i586 x86_64) [New Version: 2.6.12]:
- puppet-2.6.12-0.14.1
- puppet-server-2.6.12-0.14.1
- SUSE Linux Enterprise Server 11 SP1 (i586 ia64 ppc64 s390x x86_64) [New Version: 2.6.12]:
- puppet-2.6.12-0.14.1
- puppet-server-2.6.12-0.14.1
- SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 2.6.12]:
- puppet-2.6.12-0.14.1
- SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64) [New Version: 2.6.12]:
- puppet-2.6.12-0.14.1