CVE-2012-1053
Estado: ModificadaMedia (6.9)—
The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 6.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-264
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.html
- http://projects.puppetlabs.com/issues/12457
- http://projects.puppetlabs.com/issues/12458
- http://projects.puppetlabs.com/issues/12459
- http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14
- http://puppetlabs.com/security/cve/cve-2012-1053/
- http://secunia.com/advisories/48157
- http://secunia.com/advisories/48161
- http://secunia.com/advisories/48166
- http://secunia.com/advisories/48290
- http://ubuntu.com/usn/usn-1372-1
- http://www.debian.org/security/2012/dsa-2419
- http://www.osvdb.org/79495
- http://www.securityfocus.com/bid/52158
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73445
- https://hermes.opensuse.org/messages/15087408
- http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.html
- http://projects.puppetlabs.com/issues/12457
- http://projects.puppetlabs.com/issues/12458
- http://projects.puppetlabs.com/issues/12459
- http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14
- http://puppetlabs.com/security/cve/cve-2012-1053/
- http://secunia.com/advisories/48157
- http://secunia.com/advisories/48161
- http://secunia.com/advisories/48166
- http://secunia.com/advisories/48290
- http://ubuntu.com/usn/usn-1372-1
- http://www.debian.org/security/2012/dsa-2419
- http://www.osvdb.org/79495
- http://www.securityfocus.com/bid/52158
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73445
- https://hermes.opensuse.org/messages/15087408
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-1053",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-05-29T20:55:07.057",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.html",
"source": "cve@mitre.org"
},
{
"url": "http://projects.puppetlabs.com/issues/12457",
"source": "cve@mitre.org"
},
{
"url": "http://projects.puppetlabs.com/issues/12458",
"source": "cve@mitre.org"
},
{
"url": "http://projects.puppetlabs.com/issues/12459",
"source": "cve@mitre.org"
},
{
"url": "http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14",
"source": "cve@mitre.org"
},
{
"url": "http://puppetlabs.com/security/cve/cve-2012-1053/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/48157",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/48161",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/48166",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/48290",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://ubuntu.com/usn/usn-1372-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2012/dsa-2419",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/79495",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/52158",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73445",
"source": "cve@mitre.org"
},
{
"url": "https://hermes.opensuse.org/messages/15087408",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00003.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://projects.puppetlabs.com/issues/12457",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://projects.puppetlabs.com/issues/12458",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://projects.puppetlabs.com/issues/12459",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://projects.puppetlabs.com/projects/1/wiki/Release_Notes#2.6.14",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://puppetlabs.com/security/cve/cve-2012-1053/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48157",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48161",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48166",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48290",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://ubuntu.com/usn/usn-1372-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2012/dsa-2419",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/79495",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/52158",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73445",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hermes.opensuse.org/messages/15087408",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups."
},
{
"lang": "es",
"value": "El método change_user en el SUIDManager SUIDManager (lib/puppet/util/suidmanager.rb) en Puppet v2.6.x anterior a v2.6.14 y v2.7.x anterior a v2.7.11, y Puppet Enterprise (PE) Users v1.0, v1.1, v1.2.x, v2.0.x anterior a 2.0.3 no gestiona adecuadamente los privilegios de grupo, lo que permite a usuarios locales conseguir privilegios a través de vectores relacionados con (1) change_user en ciertas condiciones, (2) cambios en el eguid sin cambios asociados a la egid, o (3) la adición de la gid real a grupos complementarios."
}
],
"lastModified": "2026-06-16T23:38:54.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BEF50EE-4E4B-4641-BA34-B5024F1EF683"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CC72248-FD33-4CA0-A16E-0A174A864257"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7CEFB16E-261F-4B81-BCBE-536CAD2EC44B"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "652D28FC-7133-4C5F-95D9-3468548465B5"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEEEE59D-BC0E-4107-B55D-9B182825E557"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4ED400E-48F7-475B-A87C-A14EC63DD93D"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D827D4C2-7438-4EDD-9025-38D46CD5153C"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E73C341A-6C07-4820-B1D3-4616B634F380"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61381D4C-972F-4979-84D2-793E4C60E23E"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D8C2A71-0277-4426-8627-D6FD275EFC62"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FB3C44C-2C6C-496C-9D2E-C43FFB493C42"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD2656B0-9606-477B-BEB3-35746218BF9C"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "848F82FB-ACCE-42C0-A208-55522A030835"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.6.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0BBFAA7-BB3F-49D2-975B-01194C66D7C2"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE56BA6B-BDC4-431E-81FD-D7ED5E8783E9"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDDDFB28-1971-4CCD-93D2-ABC08FE67F4A"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "508105B4-619A-4A9D-8B2F-FE5992C1006A"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26DB96A5-A57D-452F-A452-98B11F51CAE6"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D33AF704-FA05-4EA8-BE95-0177871A810F"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "390FC5AE-4939-468C-B323-6B4E267A0F4C"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07DE4213-E233-402E-88C2-B7FF8D7B682C"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4122D8E3-24AD-4A55-9F89-C3AAD50E638D"
},
{
"criteria": "cpe:2.3:a:puppet:puppet:2.7.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF6D6B90-62BA-4944-A699-6D7C48AFD0A1"
},
{
"criteria": "cpe:2.3:a:puppetlabs:puppet:2.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1E5192CB-094F-469E-A644-2255C4F44804"
},
{
"criteria": "cpe:2.3:a:puppetlabs:puppet:2.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D17D2752-CB0D-4CC8-8604-FEBF8DEE16E0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:1.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0A584D14-197E-47EB-B394-B8B211D4B502"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:1.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFF8F62F-8782-4FD2-BC14-3F9E46881F0C"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:1.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36A3FDB9-F599-4999-A6B9-C82C7DAF5A70"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:1.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41C07E3C-4F96-4B91-8B2D-09076749FF2B"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:1.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76BD798A-9D06-4CC2-B40B-D377EBEBA5B9"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCFA5742-38F2-43BD-9C90-E4F447F55684"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1389B834-FE5B-4CF7-93CC-63E919FC58CE"
},
{
"criteria": "cpe:2.3:a:puppet:puppet_enterprise:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D8A8C568-1922-4701-BA61-DF960C43A6FD"
},
{
"criteria": "cpe:2.3:a:puppetlabs:puppet_enterprise_users:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C1C09E3-88DB-4022-B4B4-8FEE5D9CB57B"
},
{
"criteria": "cpe:2.3:a:puppetlabs:puppet_enterprise_users:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD5ED72A-0C75-4680-8283-E0AE47780B3E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}