LWN.net Logo

condor: unauthorized access

Package(s):condor CVE #(s):CVE-2008-3424
Created:August 11, 2008 Updated:October 8, 2008
Description:

From the Red Hat advisory:

A flaw was found in the way Condor interpreted wildcards in authorization lists. Certain authorization lists using wildcards in DENY rules, such as DENY_WRITE or HOSTDENY_WRITE, that conflict with the definitions in ALLOW rules, could permit authenticated remote users to submit computation jobs, even when such access should have been denied. (CVE-2008-3424)

Alerts:
Fedora FEDORA-2008-7205 2008-08-12
Red Hat RHSA-2008:0814-01 2008-08-11
Red Hat RHSA-2008:0816-01 2008-08-11

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds