|
|
| |
|
| |
torque: remote code execution
| Package(s): | torque |
CVE #(s): | CVE-2011-2193
|
| Created: | June 21, 2011 |
Updated: | September 5, 2012 |
| Description: |
From the Red Hat bugzilla:
Torque server does not check the length of the "job name" argument before
using it - this string is verified only on the client side. It is
possible to use a modified Torque client or DRMAA interface to submit a job
with an arbitrary chosen job name in terms of length and content. Thus, it
is possible for the attacker to overflow buffer and overwrite some Torque
server process internal data causing its specific behavior.
Note that this data overwriting could lead to remote code execution.
|
| Alerts: |
|
( Log in to post comments)
|
|
|