LWN.net Logo

condor: multiple vulnerabilities

Package(s):condor CVE #(s):CVE-2008-3826 CVE-2008-3828 CVE-2008-3829 CVE-2008-3830
Created:October 8, 2008 Updated:October 10, 2008
Description:

From the Red Hat advisory:

A flaw was found in the way Condor processed user submitted jobs. It was possible for a user to submit a job in a way that could cause that job to run as a different user with access to the pool. (CVE-2008-3826)

A stack based buffer overflow flaw was found in Condor's condor_schedd daemon. A user who had permissions to submit a job could do so in a manner that could cause condor_schedd to crash or, potentially, execute arbitrary code with the permissions of condor_schedd. (CVE-2008-3828)

A denial-of-service flaw was found in Condor's condor_schedd daemon. A user who had permissions to submit a job could do so in a manner that would cause condor_schedd to crash. (CVE-2008-3829)

A flaw was found in the way Condor processes allowed and denied netmasks for access control. If a configuration file contained an overlapping netmask in the allow or deny rules, it could cause that rule to be ignored, allowing unintended access. (CVE-2008-3830)

Alerts:
Fedora FEDORA-2008-8733 2008-10-09
Red Hat RHSA-2008:0911-01 2008-10-07
Red Hat RHSA-2008:0924-01 2008-10-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds