ubuntu · CVE-2012-1054

Quick triage

Priority: medium Published: 2012-02-23 05:00:00 UTC Updated: 2024-07-24 15:57:39 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2012-1054 medium priority: Ubuntu including 1 source packages (puppet), 6 status rows across 6 suites (hardy, lucid, maverick, natty, oneiric, upstream): released 5, ignored 1.

Description:

Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.

cvelogic Threat Intelligence