|
|
| |
|
| |
condor: privilege escalation
| Package(s): | condor |
CVE #(s): | CVE-2012-3416
|
| Created: | August 15, 2012 |
Updated: | September 4, 2012 |
| Description: |
From the Red Hat advisory:
Condor installations that rely solely upon host-based authentication were
vulnerable to an attacker who controls an IP, its reverse-DNS entry and has
knowledge of a target site's security configuration. With this control and
knowledge, the attacker could bypass the target site's host-based
authentication and be authorized to perform privileged actions (i.e.
actions requiring ALLOW_ADMINISTRATOR or ALLOW_WRITE). Condor deployments
using host-based authentication that contain no hostnames (IPs or IP globs
only) or use authentication stronger than host-based are not vulnerable. |
| Alerts: |
|
( Log in to post comments)
|
|
|