CVE-2013-4255 Information

Description

The policy definition evaluator in Condor 7.5.4 8.0.0 and earlier does not properly handle attributes in a (1) PREEMPT (2) SUSPEND (3) CONTINUE (4) WANT_VACATE or (5) KILL policy that evaluate to an Unconfigured Undefined or Error state which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.

Reference

http://rhn.redhat.com/errata/RHSA-2013-1171.html http://rhn.redhat.com/errata/RHSA-2013-1172.html https://bugzilla.redhat.com/show_bug.cgi?id=919401 https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1786 https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=3829

Share on: