Vulnerability Name:

CVE-2011-3872 (CCN-70970)

Assigned:2011-10-24
Published:2011-10-24
Updated:2019-07-11
Summary:Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2011-3872

Source: CONFIRM
Type: Patch
http://groups.google.com/group/puppet-announce/browse_thread/thread/e7edc3a71348f3e1

Source: CONFIRM
Type: UNKNOWN
http://puppetlabs.com/blog/important-security-announcement-altnames-vulnerability/

Source: CCN
Type: Puppet Labs Web site
A bug in Puppet 0.24.0 through 2.7.5 causes Puppet to insert the puppet master’s DNS alt names ("certdnsnames" in puppet.conf) into the X.509 Subject Alternative Name field of all certificates, rather than just the puppet master’s certificate.

Source: CCN
Type: SA46550
Puppet "certdnsnames" Puppet Master Impersonation Vulnerability

Source: SECUNIA
Type: Vendor Advisory
46550

Source: SECUNIA
Type: Vendor Advisory
46578

Source: SECUNIA
Type: UNKNOWN
46934

Source: SECUNIA
Type: UNKNOWN
46964

Source: DEBIAN
Type: DSA-2352
puppet -- programming error

Source: CCN
Type: OSVDB ID: 76623
Puppet certdnsnames Puppet Master Impersonation Weakness

Source: BID
Type: UNKNOWN
50356

Source: CCN
Type: BID-50356
Puppet 'certdnsnames' Certificate Validation Security Bypass Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1238-1

Source: UBUNTU
Type: UNKNOWN
USN-1238-2

Source: XF
Type: UNKNOWN
puppet-x509-spoofing(70970)

Source: XF
Type: UNKNOWN
puppet-x509-spoofing(70970)

Source: CONFIRM
Type: UNKNOWN
https://puppet.com/security/cve/cve-2011-3872

Vulnerable Configuration:Configuration 1:
  • cpe:/a:puppet:puppet:2.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.9:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.10:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.11:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:puppet:puppet_enterprise:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet_enterprise:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet_enterprise:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet_enterprise:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:puppetlabs:puppet_enterprise_users:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:puppetlabs:puppet_enterprise_users:1.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:puppet:puppet:2.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:puppet:puppet:2.6.10:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7702
    P
    libxml2-2-2.10.3-150500.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7724
    P
    opensc-0.22.0-150400.1.7 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51948
    P
    Security update for python-rsa (Moderate)
    2022-11-10
    oval:org.opensuse.security:def:20113872
    V
    CVE-2011-3872
    2022-09-02
    oval:org.opensuse.security:def:6346
    P
    Security update for libEMF (Moderate) (in QA)
    2022-08-29
    oval:org.opensuse.security:def:5334
    P
    Security update for postgresql13 (Important)
    2022-08-26
    oval:org.opensuse.security:def:6147
    P
    Security update for bluez (Important)
    2022-08-25
    oval:org.opensuse.security:def:6138
    P
    Security update for java-1_8_0-openjdk (Important)
    2022-08-16
    oval:org.opensuse.security:def:42426
    P
    Security update for mokutil (Moderate)
    2022-08-03
    oval:org.opensuse.security:def:6129
    P
    Security update for tiff (Low)
    2022-08-03
    oval:org.opensuse.security:def:6096
    P
    Security update for the Linux Kernel (Important)
    2022-07-12
    oval:org.opensuse.security:def:5287
    P
    Security update for curl (Important)
    2022-07-06
    oval:org.opensuse.security:def:123912
    P
    puppet-3.8.5-15.9.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:5276
    P
    Security update for openssl-1_0_0 (Important)
    2022-06-16
    oval:org.opensuse.security:def:6071
    P
    Security update for xen (Important)
    2022-06-14
    oval:org.opensuse.security:def:5263
    P
    Security update for pcp (Moderate)
    2022-05-27
    oval:org.opensuse.security:def:5245
    P
    Security update for poppler (Moderate)
    2022-05-18
    oval:org.opensuse.security:def:6331
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:5241
    P
    Security update for the Linux Kernel (Important)
    2022-05-16
    oval:org.opensuse.security:def:5219
    P
    Security update for netatalk (Important)
    2022-04-13
    oval:org.opensuse.security:def:5212
    P
    Security update for mozilla-nss (Important)
    2022-04-05
    oval:org.opensuse.security:def:5996
    P
    Security update for python3 (Moderate)
    2022-03-30
    oval:org.opensuse.security:def:6192
    P
    Security update for libcaca (Important)
    2022-03-14
    oval:org.opensuse.security:def:5368
    P
    Security update for MozillaFirefox (Important)
    2022-03-14
    oval:org.opensuse.security:def:6170
    P
    Security update for jasper (Moderate)
    2022-02-24
    oval:org.opensuse.security:def:5349
    P
    Security update for php74 (Moderate)
    2022-02-21
    oval:org.opensuse.security:def:6160
    P
    Security update for apache2 (Important)
    2022-02-16
    oval:org.opensuse.security:def:5254
    P
    Security update for expat (Important)
    2022-01-25
    oval:org.opensuse.security:def:5211
    P
    Security update for virglrenderer (Important)
    2022-01-18
    oval:org.opensuse.security:def:113360
    P
    ruby2.2-rubygem-puppet-3.8.7-2.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:31754
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:55285
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:5936
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:6489
    P
    Security update for postgresql10 (Important)
    2021-12-14
    oval:org.opensuse.security:def:5915
    P
    Security update for python-Babel (Important)
    2021-12-06
    oval:org.opensuse.security:def:5914
    P
    Security update for glib-networking (Important)
    2021-12-06
    oval:org.opensuse.security:def:6238
    P
    Security update for netcdf (Important)
    2021-11-25
    oval:org.opensuse.security:def:26167
    P
    Security update for php72 (Moderate)
    2021-11-19
    oval:org.opensuse.security:def:31703
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:6216
    P
    Security update for qemu (Important)
    2021-11-03
    oval:org.opensuse.security:def:6208
    P
    Security update for ncurses (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:31289
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-10-18
    oval:org.opensuse.security:def:6975
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:7189
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP2) (Important)
    2021-10-14
    oval:org.opensuse.security:def:26145
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:106767
    P
    ruby2.2-rubygem-puppet-3.8.7-2.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:5847
    P
    Security update for postgresql12 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:32196
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:26136
    P
    Security update for gd (Moderate)
    2021-09-23
    oval:org.opensuse.security:def:5869
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:31278
    P
    Security update for xen (Important)
    2021-09-23
    oval:org.opensuse.security:def:31277
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-09-23
    oval:org.opensuse.security:def:5839
    P
    Security update for grafana-piechart-panel (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:42217
    P
    Security update for libesmtp (Important)
    2021-09-21
    oval:org.opensuse.security:def:7167
    P
    Security update for the Linux Kernel (Live Patch 8 for SLE 15 SP2) (Important)
    2021-09-16
    oval:org.opensuse.security:def:5112
    P
    Security update for grilo (Important)
    2021-09-09
    oval:org.opensuse.security:def:5829
    P
    Security update for apache2 (Important)
    2021-09-03
    oval:org.opensuse.security:def:51651
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:26110
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:5816
    P
    Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3 (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:5807
    P
    Security update for qemu (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:32982
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:51633
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:5093
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:5798
    P
    Security update for python-reportlab (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:32151
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-07-27
    oval:org.opensuse.security:def:26092
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:5765
    P
    Security update for dbus-1 (Important)
    2021-07-12
    oval:org.opensuse.security:def:31644
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:26078
    P
    Security update for libxml2 (Moderate)
    2021-06-18
    oval:org.opensuse.security:def:5740
    P
    Security update for libjpeg-turbo (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:32943
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:6284
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:77624
    P
    puppet-3.8.5-14.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11997
    P
    puppet-3.8.5-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42683
    P
    puppet-2.7.26-0.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:76740
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36276
    P
    puppet-2.7.26-0.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:77993
    P
    puppet-3.8.5-15.9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12328
    P
    puppet-3.8.5-14.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:76996
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11444
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12697
    P
    puppet-3.8.5-15.9.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36490
    P
    libssh2-1-1.2.9-4.2.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:77293
    P
    puppet-3.8.5-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11700
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36532
    P
    pam-devel-1.1.5-0.15.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32109
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:6900
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP1) (Important)
    2021-05-25
    oval:org.opensuse.security:def:51889
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:32095
    P
    Security update for libxml2 (Important)
    2021-05-19
    oval:org.opensuse.security:def:5031
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:5665
    P
    Security update for librsvg (Important)
    2021-04-28
    oval:org.opensuse.security:def:6881
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:26039
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:26029
    P
    Security update for the Linux Kernel (Important)
    2021-04-15
    oval:org.opensuse.security:def:5646
    P
    Security update for wpa_supplicant (Moderate)
    2021-04-13
    oval:org.opensuse.security:def:7064
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP2) (Important)
    2021-04-07
    oval:org.opensuse.security:def:6866
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:5631
    P
    Security update for tomcat (Important)
    2021-04-01
    oval:org.opensuse.security:def:31363
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:5977
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:31743
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:6467
    P
    Security update for openssl-1_0_0 (Moderate)
    2021-03-11
    oval:org.opensuse.security:def:31742
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:5962
    P
    Recommended update for clamav-database (Important)
    2021-03-08
    oval:org.opensuse.security:def:6465
    P
    Security update for openldap2 (Important)
    2021-03-08
    oval:org.opensuse.security:def:5187
    P
    Security update for glibc (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:26198
    P
    Security update for avahi (Moderate)
    2021-02-23
    oval:org.opensuse.security:def:32261
    P
    Security update for krb5-appl (Important)
    2021-02-19
    oval:org.opensuse.security:def:31731
    P
    Security update for java-1_7_1-ibm (Important)
    2021-02-18
    oval:org.opensuse.security:def:7000
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32239
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-02-10
    oval:org.opensuse.security:def:32200
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:5078
    P
    Security update for MozillaFirefox (Important)
    2021-01-29
    oval:org.opensuse.security:def:51912
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:32097
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:4963
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:6440
    P
    Security update for the Linux Kernel (Important)
    2020-12-10
    oval:org.opensuse.security:def:7051
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:13232
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36019
    P
    puppet-2.6.18-0.4.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35633
    P
    python-2.6.0-8.9.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35692
    P
    evince-2.28.2-0.7.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:46352
    P
    puppet-3.6.2-3.62 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35741
    P
    libcap-progs-2.11-2.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35780
    P
    logwatch-7.3.6-65.72.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35808
    P
    perl-spamassassin-3.3.1-10.8.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35810
    P
    puppet-2.6.12-0.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35852
    P
    Mesa-32bit-9.0.3-0.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:5501
    P
    Security update for squid (Critical)
    2020-12-02
    oval:org.opensuse.security:def:5510
    P
    Security update for openldap2 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:5519
    P
    Security update for nodejs10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:5532
    P
    Security update for apache-commons-httpclient (Important)
    2020-12-02
    oval:org.opensuse.security:def:4985
    P
    Security update for nodejs8 (Important)
    2020-12-02
    oval:org.opensuse.security:def:5508
    P
    Security update for wicked (Important)
    2020-12-02
    oval:org.opensuse.security:def:4955
    P
    Security update for mariadb (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:5516
    P
    Security update for xen (Important)
    2020-12-02
    oval:org.opensuse.security:def:5538
    P
    Security update for openldap2 (Important)
    2020-12-02
    oval:org.opensuse.security:def:5443
    P
    Security update for libssh (Important)
    2020-12-02
    oval:org.opensuse.security:def:5584
    P
    Security update for the Linux Kernel (Important)
    2020-12-02
    oval:org.opensuse.security:def:5468
    P
    Security update for tomcat (Important)
    2020-12-02
    oval:org.opensuse.security:def:25361
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25901
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:31960
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52796
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:54362
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51785
    P
    Security update for python-azure-agent (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52508
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:53190
    P
    Security update for salt (Important)
    2020-12-01
    oval:org.opensuse.security:def:6529
    P
    wireshark on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32052
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:52962
    P
    Security update for php7 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32735
    P
    libtiff3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34994
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:52648
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:51806
    P
    Security update for ldb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53228
    P
    Security update for sysstat (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51489
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:53247
    P
    Security update for libcaca (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7033
    P
    libexempi3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26774
    P
    libxml2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32774
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31485
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:35005
    P
    Security update for gnutls
    2020-12-01
    oval:org.opensuse.security:def:52886
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP1) (Important)
    2020-12-01
    oval:org.opensuse.security:def:26247
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53309
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:6743
    P
    libpoppler-glib8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51511
    P
    Security update for binutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53355
    P
    Security update for freetds (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7042
    P
    libgme0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26809
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25568
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35089
    P
    Security update for kdebase4-runtime
    2020-12-01
    oval:org.opensuse.security:def:53059
    P
    Initial update for kernel-azure (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52078
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26286
    P
    Security update for libcdio (Low)
    2020-12-01
    oval:org.opensuse.security:def:54585
    P
    libpng12-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26251
    P
    Security update for zziplib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32352
    P
    Security update for squid3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:53447
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25569
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:35225
    P
    Security update for liblouis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53165
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52363
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26300
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32305
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:54659
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52116
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26402
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32408
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53521
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35326
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:53331
    P
    Security update for bind (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52471
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26344
    P
    Security update for mbedtls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25372
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:52062
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26455
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:32457
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53559
    P
    Security update for apache2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:51786
    P
    Security update for docker-runc (Important)
    2020-12-01
    oval:org.opensuse.security:def:35383
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53616
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:52563
    P
    Security update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:26982
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25436
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31495
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:52168
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:26504
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:32496
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53640
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:51232
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51808
    P
    Security update for openwsman (Important)
    2020-12-01
    oval:org.opensuse.security:def:35473
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:53724
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52637
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27017
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25825
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:25564
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:31587
    P
    Security update for tcpdump (Important)
    2020-12-01
    oval:org.opensuse.security:def:52334
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:26543
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32518
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54916
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31486
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53816
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52675
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:25826
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25645
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:52619
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26557
    P
    gnome-screensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32562
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54990
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52485
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31497
    P
    Security update for python-lxml
    2020-12-01
    oval:org.opensuse.security:def:52186
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53890
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52756
    P
    Security update for the Linux Kernel (Live Patch 15 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:6751
    P
    libraw9 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25702
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52727
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:26601
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33200
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25580
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31571
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52359
    P
    Security update for grafana, grafana-piechart-panel, grafana-status-panel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6365
    P
    libblkid1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53928
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54032
    P
    libjavascriptcoregtk-1_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52117
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:6773
    P
    libvdpau1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25786
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31887
    P
    Security update for emacs (Important)
    2020-12-01
    oval:org.opensuse.security:def:52819
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP1) (Important)
    2020-12-01
    oval:org.opensuse.security:def:27239
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33239
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34993
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25644
    P
    Security update for taglib (Low)
    2020-12-01
    oval:org.opensuse.security:def:52465
    P
    Security update for clamav-database (Important)
    2020-12-01
    oval:org.opensuse.security:def:54009
    P
    libXv1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54106
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51488
    P
    Security update for osc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52139
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:6819
    P
    procmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25937
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31943
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52893
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:27274
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25772
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31795
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:52631
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:52279
    P
    Security update for fontforge (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25990
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31992
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:52931
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:6798
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51233
    P
    Security update for evince (Important)
    2020-12-01
    oval:org.opensuse.security:def:25853
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31852
    P
    Recommended udpate for SUSE Manager Client Tools (Low)
    2020-12-01
    oval:org.opensuse.security:def:52916
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:6498
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55359
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52517
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32031
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:53012
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:6820
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51255
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25910
    P
    Security update for gstreamer-0_10-plugins-base (Low)
    2020-12-01
    oval:org.opensuse.security:def:31939
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:53024
    P
    Security update for php7 (Important)
    2020-12-01
    oval:org.opensuse.security:def:6507
    P
    shim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25360
    P
    Security update for xrdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:25837
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:31828
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:52690
    P
    Security update for the Linux Kernel (Live Patch 7 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:32053
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:54288
    P
    libmysqlclient18 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52486
    P
    Security update for MozillaThunderbird and mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:51395
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25994
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53116
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6516
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:21321
    P
    USN-1238-1 -- puppet vulnerability
    2014-06-30
    oval:org.mitre.oval:def:15307
    P
    DSA-2352-1 puppet -- programming error
    2014-06-23
    BACK
    puppet puppet 2.6.0
    puppet puppet 2.6.1
    puppet puppet 2.6.2
    puppet puppet 2.6.3
    puppet puppet 2.6.4
    puppet puppet 2.6.5
    puppet puppet 2.6.6
    puppet puppet 2.6.7
    puppet puppet 2.6.8
    puppet puppet 2.6.9
    puppet puppet 2.6.10
    puppet puppet 2.6.11
    puppet puppet 2.7.2
    puppet puppet 2.7.3
    puppet puppet 2.7.4
    puppet puppet 2.7.5
    puppetlabs puppet 2.7.0
    puppetlabs puppet 2.7.1
    puppet puppet enterprise 1.2.0
    puppet puppet enterprise 1.2.1
    puppet puppet enterprise 1.2.2
    puppet puppet enterprise 1.2.3
    puppetlabs puppet enterprise users 1.0
    puppetlabs puppet enterprise users 1.1
    puppetlabs puppet 2.6.3
    puppetlabs puppet 2.6.4
    puppetlabs puppet 2.7.4
    puppetlabs puppet 2.6.10