CVE-2014-3684
Summary
| CVE | CVE-2014-3684 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-30 14:55:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted executable. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:S/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.3 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.3.1 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.4 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.4.1 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.5 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.6 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.6.1 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.7 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.8 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 4.2.9 | All | All | All |
| Application | Adaptivecomputing | Torque Resource Manager | 5.0.0-1_43d8f09a | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2015:124 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Security Advisory SA61350 - TORQUE Resource Manager "tm_adopt()" Denial of Service Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - tm_adopt() vulnerability in TORQUE Resource Manager | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| [SECURITY] Fedora 20 Update: torque-4.2.10-3.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 21 Update: torque-4.2.10-3.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Mageia Advisory: MGASA-2014-0408 - Updated torque packages fix CVE-2014-3684 | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| [SECURITY] Fedora 22 Update: torque-4.2.10-3.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Debian -- Security Information -- DSA-3058-1 torque | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA61960 - Debian update for torque - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: tm_adopt() vulnerability in TORQUE Resource Manager | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.