Back to search
CVE-2016-9686
Published: Feb 8, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.
| Vendor | Product | Versions |
|---|---|---|
Puppet | Puppet Enterprise | affected 2015.3.xaffected 2016.x prior to 2016.4.3affected 2016.5.1. |
References
https://puppet.com/security/cve/cve-2016-9686
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now