SUSE-SU-2018:0571-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20180571-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0571-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:0571-1
Related
Published
2018-03-01T13:34:13Z
Modified
2018-03-01T13:34:13Z
Summary
Security update for puppet
Details

This update for puppet fixes the following issues:

  • CVE-2017-10689: Reset permissions when unpacking tar in PMT. When using minitar, files were unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions (bsc#1080288)
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 / puppet

Package

Name
puppet
Purl
purl:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.5-15.9.1

Ecosystem specific

{
    "binaries": [
        {
            "puppet": "3.8.5-15.9.1"
        }
    ]
}

SUSE:Linux Enterprise Desktop 12 SP3 / puppet

Package

Name
puppet
Purl
purl:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.5-15.9.1

Ecosystem specific

{
    "binaries": [
        {
            "puppet": "3.8.5-15.9.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Advanced Systems Management 12 / puppet

Package

Name
puppet
Purl
purl:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.5-15.9.1

Ecosystem specific

{
    "binaries": [
        {
            "puppet": "3.8.5-15.9.1",
            "puppet-server": "3.8.5-15.9.1"
        }
    ]
}