Torque CVE-2013-4319 Remote Arbitrary Code Execution Vulnerability
BID:62273
Info
Torque CVE-2013-4319 Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 62273 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-4319 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2013 12:00AM |
| Updated: | Apr 13 2015 10:24PM |
| Credit: | John Fitzpatrick of MWR InfoSecurity |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Torque CVE-2013-4319 Remote Arbitrary Code Execution Vulnerability
Torque is prone to a remote arbitrary code-execution vulnerability because the 'pbs_mom' component fails to properly authenticate connections.
Attackers can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. Successfully exploiting this issue allows attackers to execute arbitrary code with root privileges.
Torque is prone to a remote arbitrary code-execution vulnerability because the 'pbs_mom' component fails to properly authenticate connections.
Attackers can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. Successfully exploiting this issue allows attackers to execute arbitrary code with root privileges.
References
Torque CVE-2013-4319 Remote Arbitrary Code Execution Vulnerability
References:
References:
- TORQUE Homepage (Cluster Resources)