CVE Database
/

CVE-2011-3872

Back to search

CVE-2011-3872

Published: Oct 27, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

46550
third-party-advisory
x_refsource_SECUNIA
USN-1238-2
vendor-advisory
x_refsource_UBUNTU
puppet-x509-spoofing(70970)
vdb-entry
x_refsource_XF
46578
third-party-advisory
x_refsource_SECUNIA
46934
third-party-advisory
x_refsource_SECUNIA
50356
vdb-entry
x_refsource_BID
46964
third-party-advisory
x_refsource_SECUNIA
USN-1238-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now