CVE-2012-1987

Unspecified vulnerability in Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys to (1) cause a denial of service (memory consumption) via a REST request to a stream that triggers a thread block, as demonstrated using CVE-2012-1986 and /dev/random; or (2) cause a denial of service (filesystem consumption) via crafted REST requests that use "a marshaled form of a Puppet::FileBucket::File object" to write to arbitrary file locations.

Published: 2012-05-29 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-1987 is rated Moderate Risk (44.8/100): CVSS Low severity, with medium exploitation likelihood (EPSS 2.55%). Core evidence: EPSS rose +1.79% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2012-1987

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.76% 2.55% +1.79%
2 2025-11-21 0.66% 0.76% +0.10%
3 2025-03-30 0.66%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-1987

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.5 2.0 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
6.8 2.9 [email protected]

Weakness enumeration for CVE-2012-1987

GitHub Security Advisory for CVE-2012-1987

GHSA-v58w-6xc2-w799 · Severity: low · Ecosystem: rubygems — Puppet Denial of Service and Arbitrary File Write

OS Trackers for CVE-2012-1987

vendor priority summary link
debian not yet assigned CVE-2012-1987 not yet assigned priority: Debian including 1 source packages (puppet), 1 status rows across 1 suites (bullseye): resolved 1. https://security-tracker.debian.org/tracker/CVE-2012-1987
gentoo high CVE-2012-1987: 1 GLSA(s) (201208-02), 1 atom(s) (app-admin/puppet); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2012-1987
redhat low https://access.redhat.com/security/cve/CVE-2012-1987
suse medium CVE-2012-1987 severity moderate: SUSE including 7 source package names (puppet-2.6.12-0.14.1, puppet-2.6.18-0.4.2, …), 7 product×package rows across 3 product lines (SUSE Linux Enterprise Server 11 SP1-TERADATA, SUSE Linux Enterprise Server 11 SP3, SUSE Linux Enterprise Server 11 SP4): Fixed 7. https://www.suse.com/security/cve/CVE-2012-1987/
ubuntu medium CVE-2012-1987 medium priority: Ubuntu including 1 source packages (puppet), 6 status rows across 6 suites (hardy, lucid, maverick, natty, oneiric, upstream): released 3, ignored 2, needs-triage 1. https://ubuntu.com/security/CVE-2012-1987

Affected software / configurations for CVE-2012-1987

Vendor Product Version Raw CPE
puppet puppet >= 2.6.0, < 2.6.15 cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*
puppet puppet >= 2.7.0, < 2.7.13 cpe:2.3:a:puppet:puppet:*:*:*:*:*:*:*:*
puppet puppet_enterprise >= 1.0, < 2.5.1 cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*

References for CVE-2012-1987

URL Tags
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079227.html Broken Link
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079289.html Broken Link
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/080003.html Broken Link
http://projects.puppetlabs.com/issues/13552 Broken Link Vendor Advisory
http://projects.puppetlabs.com/issues/13553 Broken Link Vendor Advisory
http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.15 Broken Link
http://puppetlabs.com/security/cve/cve-2012-1987/ Broken Link Vendor Advisory
http://puppetlabs.com/security/cve/cve-2012-1987/hotfixes/ Broken Link Vendor Advisory
http://secunia.com/advisories/48743 Broken Link Vendor Advisory
http://secunia.com/advisories/48748 Broken Link Vendor Advisory
http://secunia.com/advisories/48789 Broken Link Vendor Advisory
http://secunia.com/advisories/49136 Broken Link Vendor Advisory
http://ubuntu.com/usn/usn-1419-1 Third Party Advisory
http://www.debian.org/security/2012/dsa-2451 Mailing List Third Party Advisory
http://www.osvdb.org/81308 Broken Link
http://www.securityfocus.com/bid/52975 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/74794 Third Party Advisory
https://hermes.opensuse.org/messages/14523305 Broken Link
https://hermes.opensuse.org/messages/15087408 Broken Link
cvelogic Threat Intelligence