puppet 2.6.1-0ubuntu2.2 source package in Ubuntu

Changelog

puppet (2.6.1-0ubuntu2.2) maverick-security; urgency=low

  * SECURITY UPDATE: k5login can overwrite arbitrary files as root
    - debian/patches/CVE-2011-3869.patch: adjust type/k5login.rb to securely
      open the file before writing to it as root
    - CVE-2011-3869
  * SECURITY UPDATE: didn't drop privileges before creating and changing
    permissions on SSH keys
    - debian/patches/CVE-2011-3870.patch: adjust ssh_authorized_key/parsed.rb
      to drop privileges before creating the ssh directory and setting
      permissions
    - CVE-2011-3870
  * SECURITY UPDATE: fix predictable temporary filename in ralsh
    - debian/patches/CVE-2011-3871.patch: adjust application/resource.rb to
      use an unpredictable filename
    - CVE-2011-3871
  * SECURITY UPDATE: file indirector injection, similar to CVE-2011-3848
    - secure-indirector-file-backed-terminus-base-cla.patch: Since the
      indirector file backed terminus base class is only used by the test
      suite, remove it and update test cases to use a continuing class.
 -- Jamie Strandboge <email address hidden>   Fri, 30 Sep 2011 09:04:20 -0500

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Maverick
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
admin
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Maverick: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
puppet_2.6.1.orig.tar.gz 1.5 MiB 105df2a835c7b147c5b96c5b6b6217c61443f28472b21b7d66ef34c8eece9073
puppet_2.6.1-0ubuntu2.2.debian.tar.gz 40.8 KiB f3f089169e810316cfe92b0f7adb9029a0c111eb6e023450d9a832c0f3136bc0
puppet_2.6.1-0ubuntu2.2.dsc 2.2 KiB ca24eb2029d91d490a06c67aa78914c7e05620bd5870ed6d779f8005cb003703

View changes file

Binary packages built by this source

puppet: No summary available for puppet in ubuntu maverick.

No description available for puppet in ubuntu maverick.

puppet-common: No summary available for puppet-common in ubuntu maverick.

No description available for puppet-common in ubuntu maverick.

puppet-el: No summary available for puppet-el in ubuntu maverick.

No description available for puppet-el in ubuntu maverick.

puppet-testsuite: No summary available for puppet-testsuite in ubuntu maverick.

No description available for puppet-testsuite in ubuntu maverick.

puppetmaster: No summary available for puppetmaster in ubuntu maverick.

No description available for puppetmaster in ubuntu maverick.

puppetmaster-common: No summary available for puppetmaster-common in ubuntu maverick.

No description available for puppetmaster-common in ubuntu maverick.

puppetmaster-passenger: No summary available for puppetmaster-passenger in ubuntu maverick.

No description available for puppetmaster-passenger in ubuntu maverick.

vim-puppet: No summary available for vim-puppet in ubuntu maverick.

No description available for vim-puppet in ubuntu maverick.