~ubuntu-branches/ubuntu/natty/puppet/natty-security

Viewing all changes in revision 57.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2012-07-10 08:24:35 UTC
  • Revision ID: package-import@ubuntu.com-20120710082435-8jt6vcsyqk09tupc
Tags: 2.6.4-2ubuntu2.10
* SECURITY UPDATE: multiple July 2012 security issues
  - debian/patches/2.6.4-Puppet-July-2012-CVE-fixes.patch: fix multiple
    security issues. Patch from upstream, with an additional fix to
    lib/puppet/reports/store.rb.
  - CVE-2012-3864: arbitrary file read on master from authenticated
    clients
  - CVE-2012-3865: arbitrary file delete or denial of service on master
    from authenticated clients
  - CVE-2012-3867: insufficient input validation for agent cert hostnames

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: