Announce: Puppet 3.1.1 Available [ Security Release ]

Showing 1-1 of 1 messages
Announce: Puppet 3.1.1 Available [ Security Release ] Moses Mendoza 3/12/13 10:33 AM
Puppet 3.1.1 is now available. 3.1.1 addresses several security
vulnerabilities discovered in the 3.x line of Puppet. These
vulnerabilities have been assigned Mitre CVE numbers CVE-2013-1640,
CVE-2013-1652, CVE-2013-1653, CVE-2013-1654, CVE-2013-1655 and

All users of Puppet 3.1.0 and earlier are strongly encouraged to
upgrade to 3.1.1.

For more information on these vulnerabilities, please visit, or visit,,,,, and

Downloads are available at:
 * Source

Windows package is available at

RPMs are available at or /fedora

Debs are available at

Mac package is available at

Gems are available via rubygems at or by using `gem
install puppet --version=3.1.1`

See the Verifying Puppet Download section at:

Please report feedback via the Puppet Labs Redmine site, using an
affected puppet version of 3.1.1:

## Changelog ##

Andrew Parker (3):
      3b0178f (#14093) Cleanup tests for template functionality
      4ca17d9 (#14093) Remove unsafe attributes from TemplateWrapper
      f1d0731 (#14093) Restore access to the filename in the template

Jeff McCune (2):
      52be043 (#19151) Reject SSLv2 SSL handshakes and ciphers
      b9023b0 (#19531) (CVE-2013-2275) Only allow report save from the
node matching the certname

Josh Cooper (7):
      f63ed48 Fix module tool acceptance test
      c42e608 Run openssl from windows when trying to downgrade master
      8d199b2 Remove unnecessary rubygems require
      3e493e1 Don't assume puppetbindir is defined
      166bf79 Display SSL messages so we can match our regex
      0328aaf Don't require openssl client to return 0 on failure
      406725d Don't assume master supports SSLv2

Justin Stoller (6):
      cb607d9 Acceptance tests for CVEs 2013 (1640, 1652, 1653, 1654,
2274, 2275)
      611b12d Separate tests for same CVEs into separate files
      f6e1987 We can ( and should ) use grep instead of grep -E
      672af80 add quotes around paths for windows interop
      28d80f0 remove tests that do not run on 3.1+
      b87b719 run curl against the master on the master

Moses Mendoza (1):
      6c3dd98 Update PUPPETVERSION for 3.1.1

Nick Lewis (3):
      940594b (#19393) Safely load YAML from the network
      7da9559 Always read request body when using Rack
      8f82131 Fix order-dependent test failure in network/authorization_spec

Patrick Carlisle (3):
      eef6d38 (#19391) (CVE-2013-1652) Disallow use_node compiler
parameter for remote requests
      f877cf5 (#19392) (CVE-2013-1653) Validate instances passed to indirector
      eb71909 (#19392) Don't validate key for certificate_status

Pieter van de Bruggen (1):
      f6dbe99 Updating module tool acceptance tests with new expectations.