CVE-2016-5716
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-5716
Vendor advisory: security@puppet.com — https://puppet.com/security/cve/pe-console-oct-2016
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bullseye | fixed | 0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| puppet | puppet_enterprise | 2015.2.0 | |
| puppet | puppet_enterprise | 2015.2.1 | |
| puppet | puppet_enterprise | 2015.2.2 | |
| puppet | puppet_enterprise | 2015.2.3 | |
| puppet | puppet_enterprise | 2015.3.0 | |
| puppet | puppet_enterprise | 2015.3.1 | |
| puppet | puppet_enterprise | 2015.3.2 | |
| puppet | puppet_enterprise | 2015.3.3 | |
| puppet | puppet_enterprise | 2016.1.1 | |
| puppet | puppet_enterprise | 2016.1.2 | |
| puppet | puppet_enterprise | 2016.2.0 | |
| puppet | puppet_enterprise | 2016.2.1 | |
References
CWEs
CWE-134
Verify integrity in audit chain (admin only). AS-IS.