~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2012-1987

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2012-04-11 01:00:00
2
 
Candidate: CVE-2012-1987
3
 
CRD: 2012-04-11 01:00:00
4
 
PublicDate: 2012-05-29
5
 
References: 
6
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1987
7
 
 https://usn.ubuntu.com/usn/usn-1419-1
8
 
Description:
9
 
 Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before
10
 
 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x
11
 
 before 2.5.1 allows remote authenticated users with agent SSL keys to (1)
12
 
 cause a denial of service (memory consumption) via a REST request to a
13
 
 stream that triggers a thread block, as demonstrated using CVE-2012-1986
14
 
 and /dev/random; or (2) cause a denial of service (filesystem consumption)
15
 
 via crafted REST requests that use "a marshaled form of a
16
 
 Puppet::FileBucket::File object" to write to arbitrary file locations.
17
 
Ubuntu-Description: 
18
 
Notes: 
19
 
Bugs: 
20
 
 https://bugs.launchpad.net/bugs/978708
21
 
Priority: medium
22
 
Discovered-by:
23
 
Assigned-to: 
24
 
 
25
 
Patches_puppet:
26
 
upstream_puppet: needs-triage
27
 
hardy_puppet: ignored (reached end-of-life)
28
 
lucid_puppet: released (0.25.4-2ubuntu6.7)
29
 
maverick_puppet: ignored (reached end-of-life)
30
 
natty_puppet: released (2.6.4-2ubuntu2.9)
31
 
oneiric_puppet: released (2.7.1-1ubuntu3.6)
32
 
devel_puppet: released (2.7.11-1ubuntu2)