CVE-2009-4133 Information
Description
Condor 6.5.4 through 7.2.4 7.3.x and 7.4.0 as used in MRG Grid for MRG and Grid Execute Node for MRG allows remote authenticated users to queue jobs as an arbitrary user and thereby gain privileges by using a Condor command-line tool to modify an unspecified job attribute.
Reference
http://condor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1018 http://secunia.com/advisories/37766 http://secunia.com/advisories/37803 http://securitytracker.com/id?1023378 http://www.cs.wisc.edu/condor/manual/v7.4/8_3Stable_Release.htmlSECTION00931000000000000000 http://www.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2009-0001.html http://www.redhat.com/support/errata/RHSA-2009-1688.html http://www.redhat.com/support/errata/RHSA-2009-1689.html http://www.securityfocus.com/bid/37443 https://bugzilla.redhat.com/show_bug.cgi?id=544371 https://exchange.xforce.ibmcloud.com/vulnerabilities/54984
Share on: