You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa puppet

Sigurnosni nedostatak programskog paketa puppet

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2018-45d8b8ae21
2018-03-24 22:23:09.498980
——————————————————————————–

Name : puppet
Product : Fedora 27
Version : 4.10.10
Release : 1.fc27
URL : http://puppetlabs.com
Summary : A network tool for managing many disparate systems
Description :
Puppet lets you centrally manage every important aspect of your system using a
cross-platform specification language that manages all the separate elements
normally aggregated in different files, like users, cron jobs, and hosts,
along with obviously discrete elements like packages, services, and files.

——————————————————————————–
Update Information:

Update to latest puppet 4 release 4.10.10. Fixing a minor security issue.
——————————————————————————–
References:

[ 1 ] Bug #1542852 – CVE-2017-10689 puppet: Unpacking of tarballs in tar/mini.rb can create files with insecure permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1542852
——————————————————————————–

This update can be installed with the “dnf” update program. Use
su -c ‘dnf upgrade puppet’ at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list — package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

AutorDanijel Kozinovic
Cert idNCERT-REF-2018-03-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa python-paramiko

Otkriven je sigurnosni nedostatak u programskom paketu python-paramiko za operacijski sustav openSUSE. Otkriveni nedostatak potencijalnim napadačima omogućuje zaobilaženje sigurnosnih ograničenja....

Close