CVE-2012-3491
Summary
| CVE | CVE-2012-3491 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-28 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Condor Project | Condor | 7.6.0 | All | All | All |
| Application | Condor Project | Condor | 7.6.1 | All | All | All |
| Application | Condor Project | Condor | 7.6.2 | All | All | All |
| Application | Condor Project | Condor | 7.6.3 | All | All | All |
| Application | Condor Project | Condor | 7.6.4 | All | All | All |
| Application | Condor Project | Condor | 7.6.5 | All | All | All |
| Application | Condor Project | Condor | 7.6.6 | All | All | All |
| Application | Condor Project | Condor | 7.6.7 | All | All | All |
| Application | Condor Project | Condor | 7.6.8 | All | All | All |
| Application | Condor Project | Condor | 7.6.9 | All | All | All |
| Application | Condor Project | Condor | 7.8.0 | All | All | All |
| Application | Condor Project | Condor | 7.8.1 | All | All | All |
| Application | Condor Project | Condor | 7.8.2 | All | All | All |
| Application | Condor Project | Condor | 7.8.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| 8.3 Stable Release Series 7.6 | af854a3a-2127-422b-91ae-364da2661108 | research.cs.wisc.edu | |
| oss-security - Notification of upstream Condor security fixes | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Advisory SA50666 - Condor Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| HTCondor Git - condor.git/commitdiff | af854a3a-2127-422b-91ae-364da2661108 | condor-git.cs.wisc.edu | |
| Condor Multiple Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 9.3 Stable Release Series 7.8 | af854a3a-2127-422b-91ae-364da2661108 | research.cs.wisc.edu | |
| 848214 – (CVE-2012-3491) CVE-2012-3491 condor: local users can abort any idle jobs | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| HTCondor Git - condor.git/commitdiff | MITRE | condor-git.cs.wisc.edu | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.