[puppetlabs/puppet] d66e7d: (maint) Fix cve-2013-4761 acceptance test

0 views
Skip to first unread message

GitHub

unread,
Oct 1, 2014, 2:48:13 PM10/1/14
to puppet-...@googlegroups.com, puppet...@googlegroups.com
Branch: refs/heads/stable
Home: https://github.com/puppetlabs/puppet
Commit: d66e7d326433807d2b7ef33704760a9dcb375801
https://github.com/puppetlabs/puppet/commit/d66e7d326433807d2b7ef33704760a9dcb375801
Author: Josh Partlow <joshua....@puppetlabs.com>
Date: 2014-10-01 (Wed, 01 Oct 2014)

Changed paths:
M acceptance/tests/security/cve-2013-4761_injection_of_class_names_loading_code.rb

Log Message:
-----------
(maint) Fix cve-2013-4761 acceptance test

The acceptance test was removing the file that would have been executed
by the exploit, and was therefore passing regardless of the state of the
bug. Fixed so that the exploit file creates a separate exploited marker
file, and the test removes and checks only the marker file.


Commit: bb2bacc6afaf0dbb0ab4312d6774b352f0f2673f
https://github.com/puppetlabs/puppet/commit/bb2bacc6afaf0dbb0ab4312d6774b352f0f2673f
Author: Josh Partlow <joshua....@puppetlabs.com>
Date: 2014-10-01 (Wed, 01 Oct 2014)

Changed paths:
M acceptance/tests/ticket_7117_broke_env_criteria_authconf.rb

Log Message:
-----------
(PUP-3277) Change ticket_7117 env/auth.conf test to use environmentpath

This test has been removed from master, but remains in stable and is
being updated to use environmentpath as part of the general work
preparing acceptance for puppet configurations with environmentpath set
by default.


Commit: 84b58954c958c6c9f80ddf13587399cf42361dba
https://github.com/puppetlabs/puppet/commit/84b58954c958c6c9f80ddf13587399cf42361dba
Author: Josh Partlow <joshua....@puppetlabs.com>
Date: 2014-10-01 (Wed, 01 Oct 2014)

Changed paths:
M acceptance/tests/security/cve-2013-4761_injection_of_class_names_loading_code.rb
M acceptance/tests/ticket_7117_broke_env_criteria_authconf.rb

Log Message:
-----------
Merge branch 'issue/stable/pup-3277-fix-acceptance-for-default-directory-env-configuration' into stable

* issue/stable/pup-3277-fix-acceptance-for-default-directory-env-configuration:
(PUP-3277) Change ticket_7117 env/auth.conf test to use environmentpath
(maint) Fix cve-2013-4761 acceptance test


Compare: https://github.com/puppetlabs/puppet/compare/96355a181c3f...84b58954c958
Reply all
Reply to author
Forward
0 new messages