CVE-2009-4133 Information

Description

Condor 6.5.4 through 7.2.4 7.3.x and 7.4.0 as used in MRG Grid for MRG and Grid Execute Node for MRG allows remote authenticated users to queue jobs as an arbitrary user and thereby gain privileges by using a Condor command-line tool to modify an unspecified job attribute.

Reference

http://condor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1018 http://secunia.com/advisories/37766 http://secunia.com/advisories/37803 http://securitytracker.com/id?1023378 http://www.cs.wisc.edu/condor/manual/v7.4/8_3Stable_Release.htmlSECTION00931000000000000000 http://www.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2009-0001.html http://www.redhat.com/support/errata/RHSA-2009-1688.html http://www.redhat.com/support/errata/RHSA-2009-1689.html http://www.securityfocus.com/bid/37443 https://bugzilla.redhat.com/show_bug.cgi?id=544371 https://exchange.xforce.ibmcloud.com/vulnerabilities/54984

Share on: