puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://puppet.com/security/cve/cve-2009-3564 | vendor advisory |
http://projects.reductivelabs.com/issues/1806 | patch vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=475201 | issue tracking exploit third party advisory |