MEDIUM · 4.3

CVE-2012-3867

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Cer...

Vulnerability Description

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
PuppetPuppet2.6.0
PuppetlabsPuppet<= 2.6.16
DebianDebian Linux6.0
CanonicalUbuntu Linux10.04
OpensuseOpensuse11.4
SuseLinux Enterprise Desktop11
SuseLinux Enterprise Server11
PuppetPuppet Enterprise<= 2.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3867?

CVE-2012-3867 is a vulnerability with a CVSS score of 4.3 (MEDIUM). lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Cer...

How severe is CVE-2012-3867?

CVE-2012-3867 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3867?

Check the references section above for vendor advisories and patch information. Affected products include: Puppet Puppet, Puppetlabs Puppet, Debian Debian Linux, Canonical Ubuntu Linux, Opensuse Opensuse.