CVE-2009-3564
EPSS 0.05%Published: 10/6/2009Modified: 4/28/2026
Also known as:DEBIAN-CVE-2009-3564
Description
puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.
Affected packages (1)
- Debian/puppetfrom 0, < 0.25.1-3