Vulnerabilities > Canonical

DATE CVE VULNERABILITY TITLE RISK
2013-03-22 CVE-2013-1838 Resource Management Errors vulnerability in multiple products
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
network
low complexity
openstack canonical CWE-399
4.0
2013-03-22 CVE-2013-0335 Permissions, Privileges, and Access Controls vulnerability in multiple products
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
6.0
2013-03-21 CVE-2013-1052 Permissions, Privileges, and Access Controls vulnerability in Canonical Ubuntu Linux 12.10
pam-xdg-support, as used in Ubuntu 12.10, does not properly handle the PATH environment variable, which allows local users to gain privileges via unspecified vectors related to sudo.
local
low complexity
canonical CWE-264
7.2
2013-03-21 CVE-2013-1051 Improper Input Validation vulnerability in multiple products
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
4.3
2013-03-20 CVE-2013-2275 Security Bypass vulnerability in Puppet 'auth.conf'
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated nodes to submit reports for other nodes via unspecified vectors.
network
low complexity
puppet puppetlabs canonical
4.0
2013-03-20 CVE-2013-1654 Security Bypass vulnerability in Puppet
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
network
low complexity
puppet puppetlabs canonical
5.0
2013-03-20 CVE-2013-1653 Arbitrary Code Execution vulnerability in Puppet
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
network
high complexity
puppet puppetlabs canonical
7.1
2013-03-20 CVE-2013-1652 Permissions, Privileges, and Access Controls vulnerability in multiple products
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users with a valid certificate and private key to read arbitrary catalogs or poison the master's cache via unspecified vectors.
4.9
2013-03-20 CVE-2013-1640 The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2 allows remote authenticated users to execute arbitrary code via a crafted catalog request.
network
low complexity
puppet canonical
critical
9.0
2013-03-15 CVE-2013-2566 Inadequate Encryption Strength vulnerability in multiple products
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.
4.3