FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-3567

This CVE name corresponds to:

Entered Topic
2013-06-22 puppet -- Unauthenticated Remote Code Execution Vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-3567
Phase Assigned(20130521)

Description

Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.

References

Source Reference
CONFIRM https://puppetlabs.com/security/cve/cve-2013-3567/
DEBIAN DSA-2715
REDHAT RHSA-2013:1283
REDHAT RHSA-2013:1284
SUSE SUSE-SU-2013:1304
SUSE openSUSE-SU-2013:1370
UBUNTU USN-1886-1
SECUNIA 54429