CVE-2010-0156
Puppet arbitrary files overwrite via a symlink attack
EPSS 0.33%
描述
Puppet 0.24.x before 0.24.9 and 0.25.x before 0.25.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/daemonout, (2) /tmp/puppetdoc.txt, (3) /tmp/puppetdoc.tex, or (4) /tmp/puppetdoc.aux temporary file.
如何修補 CVE-2010-0156
要修補 CVE-2010-0156,請將受影響套件升級到下列已修補版本。
- Debian/puppet—升級至 0.25.4-2 或更新版本
- RubyGems/puppet—升級至 0.24.9 或更新版本
CVE-2010-0156 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.25.4-2
- >= 0.24.0, < 0.24.9