CVE-2009-4133
Summary
| CVE | CVE-2009-4133 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-23 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Condor Project | Condor | 6.5.4 | All | All | All |
| Application | Condor Project | Condor | 6.8.0 | All | All | All |
| Application | Condor Project | Condor | 6.8.1 | All | All | All |
| Application | Condor Project | Condor | 6.8.2 | All | All | All |
| Application | Condor Project | Condor | 6.8.3 | All | All | All |
| Application | Condor Project | Condor | 6.8.4 | All | All | All |
| Application | Condor Project | Condor | 6.8.5 | All | All | All |
| Application | Condor Project | Condor | 6.8.6 | All | All | All |
| Application | Condor Project | Condor | 6.8.7 | All | All | All |
| Application | Condor Project | Condor | 6.8.8 | All | All | All |
| Application | Condor Project | Condor | 6.8.9 | All | All | All |
| Application | Condor Project | Condor | 7.0.0 | All | All | All |
| Application | Condor Project | Condor | 7.0.1 | All | All | All |
| Application | Condor Project | Condor | 7.0.2 | All | All | All |
| Application | Condor Project | Condor | 7.0.3 | All | All | All |
| Application | Condor Project | Condor | 7.0.4 | All | All | All |
| Application | Condor Project | Condor | 7.0.5 | All | All | All |
| Application | Condor Project | Condor | 7.0.6 | All | All | All |
| Application | Condor Project | Condor | 7.1.0 | All | All | All |
| Application | Condor Project | Condor | 7.1.1 | All | All | All |
| Application | Condor Project | Condor | 7.1.2 | All | All | All |
| Application | Condor Project | Condor | 7.1.3 | All | All | All |
| Application | Condor Project | Condor | 7.1.4 | All | All | All |
| Application | Condor Project | Condor | 7.2.0 | All | All | All |
| Application | Condor Project | Condor | 7.2.1 | All | All | All |
| Application | Condor Project | Condor | 7.2.2 | All | All | All |
| Application | Condor Project | Condor | 7.2.3 | All | All | All |
| Application | Condor Project | Condor | 7.2.4 | All | All | All |
| Application | Condor Project | Condor | 7.3.0 | All | All | All |
| Application | Condor Project | Condor | 7.3.1 | All | All | All |
| Application | Condor Project | Condor | 7.3.2 | All | All | All |
| Application | Condor Project | Condor | 7.4.0 | All | All | All |
| Operating System | Redhat | Enterprise Mrg | 1.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CONDOR-2009-0001 | af854a3a-2127-422b-91ae-364da2661108 | www.cs.wisc.edu | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Condor Job Management Security Bypass Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 8.3 Stable Release Series 7.4 | af854a3a-2127-422b-91ae-364da2661108 | www.cs.wisc.edu | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CondorWiki: Ticket #1018 | af854a3a-2127-422b-91ae-364da2661108 | condor-wiki.cs.wisc.edu | |
| 544371 – (CVE-2009-4133) CVE-2009-4133 Condor: queue super user cannot drop privs | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Red Hat update for condor - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Condor Job Submission Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Condor Job Management Flaw Lets Local Users Gain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.