Novell Home

CVE-2011-3872

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2011-3872 at MITRE

Description

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

NVD CVSS v2 Base Score: 2.6 (AV:N/AC:H/Au:N/C:N/I:P/A:N)

Novell/SUSE information

Novell Bugzilla entry: 726372

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP1
  • puppet >= 2.6.12-0.6.1
sled11-sp1.x86-64
sles11-sp1.x86-64
sles11-sp1.ia64
sles11-sp1.ppc
sles11-sp1-vmware.x86
sles11-sp1.x86
sles11-sp1-vmware.x86-64
sles11-sp1.s390x
SAT Patch Nr: 5421
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Server 11 SP1 for VMware
  • puppet >= 2.6.12-0.6.1
  • puppet-server >= 2.6.12-0.6.1
sled11-sp1.x86-64
sles11-sp1.x86-64
sles11-sp1.ia64
sles11-sp1.ppc
sles11-sp1-vmware.x86
sles11-sp1.x86
sles11-sp1-vmware.x86-64
sles11-sp1.s390x
SAT Patch Nr: 5421
openSUSE 11.3
  • puppet >= 0.25.4-4.7.1
  • puppet-server >= 0.25.4-4.7.1
openSUSE 11.4
  • puppet >= 2.6.4-4.11.1
  • puppet-server >= 2.6.4-4.11.1

© 2014 Novell