CVE-2008-3830
Summary
| CVE | CVE-2008-3830 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-10-08 22:00:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Condor Project | Condor | 6.8.0 | All | All | All |
| Application | Condor Project | Condor | 6.8.1 | All | All | All |
| Application | Condor Project | Condor | 6.8.2 | All | All | All |
| Application | Condor Project | Condor | 6.8.3 | All | All | All |
| Application | Condor Project | Condor | 6.8.4 | All | All | All |
| Application | Condor Project | Condor | 6.8.5 | All | All | All |
| Application | Condor Project | Condor | 6.8.6 | All | All | All |
| Application | Condor Project | Condor | 6.8.7 | All | All | All |
| Application | Condor Project | Condor | 6.8.8 | All | All | All |
| Application | Condor Project | Condor | 6.8.9 | All | All | All |
| Application | Condor Project | Condor | 7.0.0 | All | All | All |
| Application | Condor Project | Condor | 7.0.1 | All | All | All |
| Application | Condor Project | Condor | 7.0.2 | All | All | All |
| Application | Condor Project | Condor | 7.0.3 | All | All | All |
| Application | Condor Project | Condor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityTracker.com Archives - Condor Bugs Let Local Users Gain Elevated Privileges or Deny Service | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| 8.3 Stable Release Series 7.0 | af854a3a-2127-422b-91ae-364da2661108 | www.cs.wisc.edu | Vendor Advisory |
| Condor Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for condor - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Condor Prior to 7.0.5 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 9 Update: condor-7.0.5-1.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Fedora update for condor - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.