CVE-2012-3867: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 2.5% chance of exploitation in the next 30 days.

lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it easier for user-assisted remote attackers to trick administrators into signing a crafted agent certificate via ANSI control sequences.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.04 only; version 11.10 only; version 12.04 only
  • Debian Debian Linux: version 6.0 only
  • Opensuse Opensuse: version 11.4 only; version 12.1 only
  • Puppet Puppet: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; version 2.6.4 only; version 2.6.5 only; …
  • Puppet Puppet Enterprise: up to and including 2.5.1
  • Puppetlabs Puppet: up to and including 2.6.16; version 2.7.0 only; version 2.7.1 only
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise Server: version 11 only

Published 2012-08-06. Last modified 2026-06-16.