Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 11 Jul 2012 12:04:50 -0600
From: Kurt Seifried <kseifried@...hat.com>
To: Moses Mendoza <moses@...petlabs.com>,
        "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Fwd: New Security Vulnerabilities in Puppet

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 07/11/2012 10:37 AM, Moses Mendoza wrote:
>>> 
>>> Vulnerability 5 Agents with certnames of IP addresses can be 
>>> impersonated (low) *Affected Versions: 2.7.x, 2.6.x If an 
>>> authenticated host with a certname of an IP address changes IP 
>>> addresses, and a second host assumes the first host's former
>>> IP address, the second host will be treated by the puppet
>>> master as the first one, giving the second host access to the
>>> first host's catalog. Note: This will not be fixed in Puppet
>>> versions prior to the forthcoming 3.x. Instead, with this
>>> announcement IP-based authentication in Puppet < 3.x is
>>> deprecated.

After some further communications with them it has been decided to
assign this issue a CVE. Please use CVE-2012-3408 for this issue.

Moses: can you confirm that a CVE page with links to the code
commits/etc will be created? Thanks.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJP/cBCAAoJEBYNRVNeJnmTy20P/RSOFcMm17lRy6ZYGZNBeXxp
AD/yyljK4eAIGOG7Nvbx9AIce1BRbb+MdxJbRqFtVhO26bRgiCGViM6I0o6lyEKH
Wh0HeLls5YtgxcNquhyJsvQQOaZ8uWRa7j09Pzm6YL0076rTxS0o7jPIt0dudRSe
u3IfbsxRWPaiurDw9XhkhxuZYGpdRf6c0XR0aHtbFwnt5Huwjf8p8GnyP16rwQcR
csr+IcWixMNZULIqh1+NoUG1uJiWYfK7LZ54q3Bm3yVWRBLzqOzao1pa9jWJwAxy
9saqOwP3TKbpDh43QcLaiT88taK71vcyezhvIlZH2LwPKk0eQSYfXAw65/bTaKIv
iCBcYgeasV5/xPYXBVglAuwqYbd1CEJTKZGenYGAPdxxrm63HIlzFeWJnL02sQZe
+6g0AVGJ6J6bHPI7TgEZsMXrEo8rfrKtAOYlDp5YsMC0YQQX4wovFbhJi0EcTeu0
uOS80adyvVDgHxdE6A3SOq3+458aCuiQ4rkp1Tf0Au/20u0zFGaytMITnJGmmFfB
NPrSNQvknuK8C/t4C7MS4lTAJu1CvTjWzeeAxgLRPb9zyEgdkEiu0yTdUH8twG5O
xfG3c0sp0jOmaKGDblTNKvMxicKppbBp2ZBmT0NbBLTG02NDCucTtOQfWizYWmDB
It5g13Hj2PmBbNOuWifm
=CbYi
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.