{"affected":[{"ecosystem_specific":{"binaries":[{"puppet":"2.7.26-0.5.3.1","puppet-server":"2.7.26-0.5.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 11 SP4","name":"puppet","purl":"pkg:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.26-0.5.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"puppet":"2.7.26-0.5.3.1","puppet-server":"2.7.26-0.5.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","name":"puppet","purl":"pkg:rpm/suse/puppet&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.7.26-0.5.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for puppet fixes the following issues:\n\n- CVE-2017-2295: Fixed a security vulnerability where an attacker could\n  force YAML deserialization in an unsafe manner, which would lead to\n  remote code execution.\n\nIn default, this update would break a backwards compatibility\nwith Puppet agents older than 3.2.2 as the SLE11 master doesn't\nsupport other fact formats than pson in default anymore.\nIn order to allow users to continue using their SLE11 agents\na patch was added that enables sending PSON from agents.\n\nFor non-SUSE clients older that 3.2.2 a new puppet master boolean option\n'dangerous_fact_formats' was added. When it's set to true it\nenables using dangerous fact formats (e.g. YAML). When it's set\nto false, only PSON fact format is accepted. (bsc#1040151),\n(bsc#1077767)\n","id":"SUSE-SU-2018:0600-1","modified":"2018-03-05T09:43:31Z","published":"2018-03-05T09:43:31Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180600-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1040151"},{"type":"REPORT","url":"https://bugzilla.suse.com/1077767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2295"}],"related":["CVE-2017-2295"],"summary":"Security update for puppet","upstream":["CVE-2017-2295"]}