CVE-2014-3250

NameCVE-2014-3250
DescriptionThe default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
puppet (PTS)jessie, jessie (lts)3.7.2-4+deb8u1fixed
stretch4.8.2-5fixed
buster5.5.10-4fixed
bullseye5.5.22-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
puppetsourcesqueeze(not affected)
puppetsourcewheezy(not affected)
puppetsource(unstable)3.7.0-1low

Notes

[squeeze] - puppet <not-affected> (Only exploitable in combination with Apache 2.4)
[wheezy] - puppet <not-affected> (Only exploitable in combination with Apache 2.4)
http://puppetlabs.com/security/cve/CVE-2014-3250

Search for package or bug name: Reporting problems