SUSE-SU-2018:0602-1

Source
https://www.suse.com/support/update/announcement/2018/suse-su-20180602-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:0602-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2018:0602-1
Related
Published
2018-03-05T09:41:06Z
Modified
2018-03-05T09:41:06Z
Summary
Security update for rubygem-puppet
Details

This update for rubygem-puppet fixes the following issues:

  • CVE-2017-10689: Reset permissions when unpacking tar in PMT. When using minitar, files were unpacked with whatever permissions are in the tarball. This is potentially unsafe, as tarballs can be easily created with weird permissions (bsc#1080288)
References

Affected packages

SUSE:Linux Enterprise Module for Advanced Systems Management 12 / rubygem-puppet

Package

Name
rubygem-puppet
Purl
pkg:rpm/suse/rubygem-puppet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.8.1-32.3.1

Ecosystem specific

{
    "binaries": [
        {
            "rubygem-puppet": "4.8.1-32.3.1",
            "ruby2.1-rubygem-puppet": "4.8.1-32.3.1"
        }
    ]
}