CVE-2009-2084
Summary
| CVE | CVE-2009-2084 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-16 23:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the slurmctld daemon, which might allow local SLURM users to modify files and gain privileges. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Llnl | Slurm | 1.2 | All | All | All |
| Application | Llnl | Slurm | 1.3 | All | All | All |
| Application | Llnl | Slurm | 1.3.1 | All | All | All |
| Application | Llnl | Slurm | 1.3.10 | All | All | All |
| Application | Llnl | Slurm | 1.3.11 | All | All | All |
| Application | Llnl | Slurm | 1.3.12 | All | All | All |
| Application | Llnl | Slurm | 1.3.2 | All | All | All |
| Application | Llnl | Slurm | 1.3.3 | All | All | All |
| Application | Llnl | Slurm | 1.3.4 | All | All | All |
| Application | Llnl | Slurm | 1.3.5 | All | All | All |
| Application | Llnl | Slurm | 1.3.6 | All | All | All |
| Application | Llnl | Slurm | 1.3.7 | All | All | All |
| Application | Llnl | Slurm | 1.3.8 | All | All | All |
| Application | Llnl | Slurm | 1.3.9 | All | All | All |
| Application | Llnl | Slurm | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 504 Gateway Time-out | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1776-1 slurm-llnl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| SLURM Supplemental Groups Privilege Escalation Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| SLURM download | SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| #524980 - SLURM daemons do not drop supplemental groups - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.