CVE-2012-1054
Publication date 23 February 2012
Last updated 24 July 2024
Ubuntu priority
Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3, when managing a user login file with the k5login resource type, allows local users to gain privileges via a symlink attack on .k5login.
References
Related Ubuntu Security Notices (USN)
- USN-1372-1
- Puppet vulnerabilities
- 23 February 2012