UBUNTU-CVE-2018-6508
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-6508
Summary:
Details: Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if you are not using puppet tasks you are not affected by this vulnerability.
References: https://ubuntu.com/security/CVE-2018-6508, https://puppet.com/security/cve/CVE-2018-6508, https://github.com/puppetlabs/puppetlabs-facter_task/commit/dd37c72e78c8a37e671e20becb05d6ceafdbd81c, https://github.com/puppetlabs/puppetlabs-puppet_conf/commit/ba434605717e16d935cba45ab38ca5866780a36b, https://github.com/puppetlabs/puppetlabs-apt/commit/81879be960d5723016e3d0b4ff155ee704261bbc, https://github.com/puppetlabs/puppetlabs-apache/commit/81bc5119ceced1faa4bf261efa4b7cd3731ef3ef, https://github.com/puppetlabs/puppetlabs-mysql/commit/da3684c79d5fe6ece826e087e8693c75ac40414c, https://www.cve.org/CVERecord?id=CVE-2018-6508
Affected packages
Package
Name: puppet-module-puppetlabs-apache
Purl: pkg:deb/ubuntu/puppet-module-puppetlabs-apache?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
