CVE-2013-4969: Canonical Ubuntu Linux

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only; version 13.10 only
  • Debian Debian Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Puppet Puppet Enterprise: from 2.0.0, before 2.8.4 (fixed in 2.8.4); from 3.1, before 3.1.1 (fixed in 3.1.1)
  • Puppetlabs Puppet: from 3.0.0, up to and including 3.3.2; from 3.4.0, before 3.4.1 (fixed in 3.4.1)

Published 2014-01-07. Last modified 2026-06-16.