Mantis - puppet
Viewing Issue Advanced Details
5090 upgrade major N/A 2013-07-11 00:43 2013-07-12 02:18
wcooley  
markp  
normal  
closed  
fixed  
none    
none  
0005090: Upgrade Puppet to 2.7.22 due to security issues
Please upgrade Puppet to 2.7.22; dublin has only 2.7.14 and kiel has only 2.7.21.

Versions prior to 2.7.22 have the following vulnerability:
"Unauthenticated Remote Code Execution Vulnerability"
  http://puppetlabs.com/security/cve/cve-2013-3567/ [^]

Prior to 2.7.21:
"Remote Code Execution Vulnerability"
  http://puppetlabs.com/security/cve/cve-2013-1640/ [^]

"Unauthenticated Remote Code Execution Vulnerability"
  http://puppetlabs.com/security/cve/cve-2013-1655/ [^]

Prior to 2.7.18:
"Arbitrary file read on the puppet master from authenticated clients"
  http://docs.puppetlabs.com/puppet/2.7/reference/release_notes.html#security-fixes [^]

There are several other security vulnerabilities covered in these releases, but these seemed to be the most pressing.
Issue History
2013-07-11 00:43 wcooley New Issue
2013-07-11 19:35 markp Status new => assigned
2013-07-11 19:35 markp Assigned To => markp
2013-07-11 19:35 markp Status assigned => acknowledged
2013-07-11 19:38 markp Note Added: 0010490
2013-07-11 19:38 markp Status acknowledged => closed
2013-07-11 19:38 markp Resolution open => fixed
2013-07-12 02:18 maciej Note Added: 0010491

Notes
(0010490)
markp   
2013-07-11 19:38   
Umm, live catalog has 2.7.22....

http://www.opencsw.org/packages/CSWpuppet/ [^]
(0010491)
maciej   
2013-07-12 02:18   
I think the problem the reporter was referring to, is the combination of these two things:

1. curl -s http://www.opencsw.org/get-it/releases/ [^] | grep -i production
<p>As of 2012, dublin is recommended for production systems.</p>

2. curl -s http://mirror.opencsw.org/opencsw/dublin/i386/5.10/catalog [^] | awk '$1 == "puppet" { print $4 }'
puppet-2.7.14,REV=2012.05.03-SunOS5.9-all-CSW.pkg.gz