LWN.net Logo

torque: remote code execution

Package(s):torque CVE #(s):CVE-2011-2193
Created:June 21, 2011 Updated:September 5, 2012
Description: From the Red Hat bugzilla:

Torque server does not check the length of the "job name" argument before using it - this string is verified only on the client side. It is possible to use a modified Torque client or DRMAA interface to submit a job with an arbitrary chosen job name in terms of length and content. Thus, it is possible for the attacker to overflow buffer and overwrite some Torque server process internal data causing its specific behavior.

Note that this data overwriting could lead to remote code execution.

Alerts:
Debian DSA-2329-1 2011-10-27
Fedora FEDORA-2011-8072 2011-06-10
Fedora FEDORA-2011-8117 2011-06-10
Mageia MGASA-2012-0254 2012-09-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds