CVE-2009-3564

EUVD-2009-3545
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Affected Products (NVD)
VendorProductVersion
reductivelabspuppet
0.24.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
puppet
bullseye
5.5.22-2
fixed
etch
no-dsa
lenny
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
puppet
dapper
dne
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
Fixed 0.24.8-2ubuntu4.1
released
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
Common Weakness Enumeration