Vulnerability Name:

CVE-2014-3250 (CCN-136231)

Assigned:2014-06-10
Published:2014-06-10
Updated:2017-12-27
Summary:The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-295
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2014-3250

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1101347

Source: XF
Type: UNKNOWN
puppet-cve20143250-info-disc(136231)

Source: CCN
Type: Puppet Web site
CVE-2014-3250 (Information Leakage Vulnerability)

Source: CONFIRM
Type: Vendor Advisory
https://puppet.com/security/cve/CVE-2014-3250

Vulnerable Configuration:Configuration 1:
  • cpe:/a:puppet:puppet:*:*:*:*:*:*:*:* (Version < 3.6.2)
  • AND
  • cpe:/a:apache:http_server:2.4.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:redhat:linux:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:puppet:puppet:0.10.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20143250
    V
    CVE-2014-3250
    2022-05-20
    oval:org.opensuse.security:def:31754
    P
    Security update for libsndfile (Important)
    2022-01-05
    oval:org.opensuse.security:def:55284
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:34011
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:34000
    P
    Security update for postgresql10 (Important)
    2021-11-22
    oval:org.opensuse.security:def:33999
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:26167
    P
    Security update for php72 (Moderate)
    2021-11-19
    oval:org.opensuse.security:def:32196
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:26110
    P
    Security update for aspell (Important)
    2021-08-25
    oval:org.opensuse.security:def:55935
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:56047
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:34475
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:30207
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:42683
    P
    puppet-2.7.26-0.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36276
    P
    puppet-2.7.26-0.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32109
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-04
    oval:org.opensuse.security:def:30075
    P
    Security update for python3 (Important)
    2021-05-17
    oval:org.opensuse.security:def:55178
    P
    Security update for java-1_7_0-openjdk (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:56009
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:26029
    P
    Security update for the Linux Kernel (Important)
    2021-04-15
    oval:org.opensuse.security:def:30001
    P
    Security update for fwupdate (Important)
    2021-04-09
    oval:org.opensuse.security:def:31743
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:31742
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:54767
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:34634
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:55843
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:57478
    P
    Security update for MozillaFirefox (Important)
    2021-01-29
    oval:org.opensuse.security:def:35528
    P
    bzip2-1.0.5-34.246 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:54627
    P
    libyaml-0-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28142
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29990
    P
    Security update for libtasn1
    2020-12-01
    oval:org.opensuse.security:def:26557
    P
    gnome-screensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27365
    P
    Xerces-c on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34741
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:32408
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27274
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27441
    P
    libdrm-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55735
    P
    Security update for libtasn1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34849
    P
    Security update for binutils
    2020-12-01
    oval:org.opensuse.security:def:25837
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:30439
    P
    Security update for xscreensaver (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32518
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27708
    P
    Security update for automake
    2020-12-01
    oval:org.opensuse.security:def:30698
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:33239
    P
    puppet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34095
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27996
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:57404
    P
    Security update for mozilla-nss
    2020-12-01
    oval:org.opensuse.security:def:26402
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30800
    P
    Security update for bsdtar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54605
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34386
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28098
    P
    Recommended update for git (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29989
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32052
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26543
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55005
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34692
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28815
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:32352
    P
    Security update for squid3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27239
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27377
    P
    boost-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55450
    P
    Security update for libreoffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34805
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25826
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:30353
    P
    Security update for w3m
    2020-12-01
    oval:org.opensuse.security:def:32496
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27651
    P
    Security update for nagios
    2020-12-01
    oval:org.opensuse.security:def:30649
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:33200
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27943
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56128
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26251
    P
    Security update for zziplib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30756
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54604
    P
    libsoup-2_4-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34329
    P
    Security update for sane-backends (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28084
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31960
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26504
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:31476
    P
    Security update for puppet
    2020-12-01
    oval:org.opensuse.security:def:28780
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26601
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27366
    P
    a2ps-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34780
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:25825
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:30296
    P
    Security update for strongswan
    2020-12-01
    oval:org.opensuse.security:def:32457
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27569
    P
    subversion on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35487
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25901
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:30594
    P
    Security update for Perl
    2020-12-01
    oval:org.opensuse.security:def:32562
    P
    libpoppler-glib4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27792
    P
    Security update for libgcrypt
    2020-12-01
    oval:org.opensuse.security:def:30737
    P
    Security update for SDL (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34231
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28045
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31828
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26455
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:31438
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:com.ubuntu.trusty:def:20143250000
    V
    CVE-2014-3250 on Ubuntu 14.04 LTS (trusty) - low.
    2017-12-11
    oval:com.ubuntu.xenial:def:201432500000000
    V
    CVE-2014-3250 on Ubuntu 16.04 LTS (xenial) - low.
    2017-12-11
    oval:com.ubuntu.xenial:def:20143250000
    V
    CVE-2014-3250 on Ubuntu 16.04 LTS (xenial) - low.
    2017-12-11
    oval:com.ubuntu.precise:def:20143250000
    V
    CVE-2014-3250 on Ubuntu 12.04 LTS (precise) - low.
    2014-12-31
    oval:org.mitre.oval:def:26240
    P
    SUSE-SU-2014:0880-1 -- Security update for puppet
    2014-09-15
    oval:org.opensuse.security:def:80112
    P
    Security update for puppet
    2014-06-30
    BACK
    puppet puppet *
    apache http server 2.4.0
    redhat linux -
    puppet puppet 0.10.0