CVE-2012-3491
CVE-2012-3491
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1fff5d40http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=848214http://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632