[CentOS] puppet, repos, security

2013-10-31 Thread ign...@vault13.lt
Hello list, I am using puppet 2.7.20 from rpmforge, with a build date of Wed 20 Mar 2013. EPEL has an even older version. Then I see this: http://puppetlabs.com/security/cve/cve-2013-3567 that was posted on the month of July 2013. Do I understand correctly, that my puppet-master is vulnerable

Re: [CentOS] puppet, repos, security

2013-10-31 Thread James Hogarth
On 31 October 2013 07:30, ign...@vault13.lt ign...@vault13.lt wrote: I am using puppet 2.7.20 from rpmforge, with a build date of Wed 20 Mar 2013. EPEL has an even older version. A very old and occasionally suspect repo (rpmforge) in terms of lack of updates (see the clamav issues a little