CVE-2018-6516
14.06.2018, 21:29
On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation.Enginsight
Vendor | Product | Version |
---|---|---|
puppet | puppet_enterprise_client_tools | 16.4.0 ≤ 𝑥 < 16.4.6 |
puppet | puppet_enterprise_client_tools | 17.3.0 ≤ 𝑥 < 17.3.6 |
puppet | puppet_enterprise_client_tools | 18.1.0 ≤ 𝑥 < 18.1.2 |
𝑥
= Vulnerable software versions

Ubuntu Releases