CVE-2009-3564

EPSS 0.05%
Published: 10/6/2009Modified: 4/28/2026
Also known as:DEBIAN-CVE-2009-3564

Description

puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.

Affected packages (1)

References (1)