Oracle Grid Engine 'sge_passwd.c' Local Buffer Overflow Vulnerability
BID:53132
Info
Oracle Grid Engine 'sge_passwd.c' Local Buffer Overflow Vulnerability
| Bugtraq ID: | 53132 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-0523 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 17 2012 12:00AM |
| Updated: | Apr 13 2015 10:08PM |
| Credit: | Oracle |
| Vulnerable: |
Sun Grid Engine 6.2 Sun Grid Engine 6.1 Grid Engine Grid Engine 2011.11 |
| Not Vulnerable: | |
Discussion
Oracle Grid Engine 'sge_passwd.c' Local Buffer Overflow Vulnerability
Oracle Grid Engine is prone to a local buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial of service.
This vulnerability affects the following supported versions:
6.1, 6.2
Oracle Grid Engine is prone to a local buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
Attackers can exploit this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial of service.
This vulnerability affects the following supported versions:
6.1, 6.2
Exploit / POC
Oracle Grid Engine 'sge_passwd.c' Local Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Grid Engine 'sge_passwd.c' Local Buffer Overflow Vulnerability
References:
References:
- Open Grid Scheduler Security (Open Grid Scheduler)
- Oracle Homepage (Oracle)
- Sun Homepage (Sun Microsystems )
- Oracle Critical Patch Update Advisory - April 2012 (Oracle)