Changelog for
puppet-2.7.6-1.13.1.i586.rpm :
* Tue Mar 26 2013 vdziewieckiAATTsuse.com-Fix numerous CVEs, see bnc#809839 puppet-2.7.11-CVEs.diff
* Wed Jul 11 2012 vdziewieckiAATTsuse.comCVEs fixed:-bnc#770828 - VUL-0: CVE-2012-3864: puppet: authenticated clients can read arbitrary files via a flaw in puppet master-bnc#770829 - VUL-0: CVE-2012-3865: puppet: arbitrary file delete / Denial of Service on Puppet Master by authenticated clients-bnc#770827 - VUL-1: CVE-2012-3866: puppet: last_run_report.yaml left world-readable-bnc#770833 - VUL-1: CVE-2012-3867: puppet: insufficient input validation for agent certificate names
* Wed Apr 11 2012 vdziewieckiAATTsuse.com-Fixed bnc#755869 VUL-0: CVE-2012-1988: puppet: Filebucket arbitrary code execution-Fixed bnc#755872 CVE-2012-1986 – Arbitrary File Read-Fixed bnc#755870 CVE-2012-1987 – Denial of Service-Fixed bnc#755871 CVE-2012-1989 – Arbitrary File Write
* Wed Jan 11 2012 vcizekAATTsuse.com- correct ownership of dirs in /var (bnc#739361)
* Tue Oct 25 2011 vcizekAATTsuse.com- update to 2.7.6 Security Fixes CVE-2011-3872 (AltNames vulnerability) Features and Enhancements User/group management on Windows Better file support on Windows Support plaintext password in Windows Bug Fixes Recognize more duplicate resources Allow multi-line exec resources Remove unnecessary deprecation warning in puppet resource Update pluginsync to only load ruby files.
* Thu Sep 29 2011 vcizekAATTsuse.com- update to 2.7.4 - enhancement + security release: fixed CVE-2011-3848 (Resist directory traversal attacks through indirections) GigabitEthernet/TenGigabitEthernet are uncorrectly parsed Don’t rely on error message to detect UAC capable platform Allow cron vars to have leading whitespace
* Thu Jun 23 2011 vcizekAATTnovell.com- update to 2.7.1 - a major feature release: Ruby 1.9 Support Deterministic Catalog Application Puppet Faces - a new API for creating new Puppet subcommands Manage Network Devices Dependency cycle reporting produces graph of the cycle- license changed to Apache-2.0 - see http://docs.puppetlabs.com/guides/faq#change-to-apache-license
* Thu May 19 2011 vcizekAATTnovell.com- using correct port for puppet in the firewall rules (bnc#694825)
* Tue Apr 05 2011 vcizekAATTnovell.com- fix logging setting (bnc#683441)
* Mon Mar 14 2011 vcizekAATTnovell.com- update to 2.6.6
* fixed many bugs
* licence has changed to GPLv2 (was GPLv2+)
* some of the new features: - Manifests can now specify arbitrary data for file contents - Managed resource attributes can now be audited - Parameterised class support in external node classifiers - New puppet inspect application
* Fri Jan 28 2011 vcizekAATTnovell.com- update to 2.6.4
* bugfixes: bnc#667867 Ship auth.conf as part of installing from source
* Tue Oct 05 2010 anickaAATTsuse.cz- update to 2.6.1
* bugfixes, manpage fixes
* Thu Aug 19 2010 anickaAATTsuse.cz- update to 2.6.0
* major release with many new configuration options and new language features
* Mon Aug 16 2010 anickaAATTsuse.cz- respect sysconfig settings (bnc#620808)
* Tue Jul 20 2010 anickaAATTsuse.cz- create puppet user not only for server package (bnc#623884)
* Tue Mar 02 2010 anickaAATTsuse.cz- update to 0.25.4
* bugfixes- create user puppet (fixes bnc#576453)
* Wed Apr 15 2009 mantelAATTsuse.de- update to 0.24.8
* Mon Apr 06 2009 mantelAATTsuse.de- add zypper.rb plugin by Leo Eraly