Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 388449 - app-admin/puppet "certdnsnames" Puppet Master Impersonation Vulnerability (CVE-2011-3872)
Summary: app-admin/puppet "certdnsnames" Puppet Master Impersonation Vulnerability (CV...
Status: RESOLVED DUPLICATE of bug 388161
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/46550/
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-10-25 13:24 UTC by Agostino Sarubbo
Modified: 2011-10-25 13:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-10-25 13:24:59 UTC
From secunia security advisory at $URL:

Description:
The vulnerability is caused due to the application inserting the puppet master's DNS alt names ("certdnsnames") into the X.509 Subject Alternative Name field of the certificate issued to the puppet agent. This can be exploited to impersonate the puppet master via Man-in-the-Middle (MitM) attacks.

Solution:
Update to: 2.6.12 and 2.7.6
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2011-10-25 13:31:23 UTC

*** This bug has been marked as a duplicate of bug 388161 ***