Condor Job Submission Security Bypass Vulnerability
BID:37443
Info
Condor Job Submission Security Bypass Vulnerability
| Bugtraq ID: | 37443 |
| Class: | Unknown |
| CVE: |
CVE-2009-4133 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2009 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Condor |
| Vulnerable: |
Redhat Enterprise MRG v1 for Red Hat Enterprise Linux ES version 4 Redhat Enterprise MRG v1 for Red Hat Enterprise Linux AS verison 4 Redhat Enterprise MRG v1 for Red Hat Enterprise Linux version 5 Condor Project Condor 7.4 |
| Not Vulnerable: |
Condor Project Condor 7.4.1 |
Discussion
Condor Job Submission Security Bypass Vulnerability
Condor is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and execute arbitrary applications in the context of other nonadministrative users and potentially gain access to their accounts.
Versions prior to Condor 7.4.1 are vulnerable.
Condor is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and execute arbitrary applications in the context of other nonadministrative users and potentially gain access to their accounts.
Versions prior to Condor 7.4.1 are vulnerable.
Exploit / POC
Condor Job Submission Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Condor Job Submission Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Condor Job Submission Security Bypass Vulnerability
References:
References:
- 8.3 Stable Release Series 7.4 (Condor)
- Vendor Homepage (Condor)
- RHSA-2009:1688-1 (Red Hat)
- RHSA-2009:1689-1 (Red Hat)