Bug#989224: [Pkg-puppet-devel] Bug#989224: puppet: Cron Provider breaks on crontab with certain environment variables (easy DOS for a user)

2021-05-29 Thread Stig Sandbeck Mathisen
Joerg Jaspert writes: > Upstream does not care, see > https://tickets.puppetlabs.com/browse/PUP-10998 >From the upstream comment, it looks a bit more like "Upstream has not understood your comment, has yet to see the issue from your perspective or thought through the security implications of

Bug#989224: puppet: Cron Provider breaks on crontab with certain environment variables (easy DOS for a user)

2021-05-29 Thread Joerg Jaspert
Source: puppet Severity: important Dear Maintainer, puppets cron provider contains a bug that allows any local user to easily turn off the puppet service. A crontab that contains an environment variable with a - breaks puppet. Change - to _ and it works. Yes, POSIX does not allow that,