LWN.net Logo

condor: privilege escalation

Package(s):condor CVE #(s):CVE-2012-3416
Created:August 15, 2012 Updated:September 4, 2012
Description: From the Red Hat advisory:

Condor installations that rely solely upon host-based authentication were vulnerable to an attacker who controls an IP, its reverse-DNS entry and has knowledge of a target site's security configuration. With this control and knowledge, the attacker could bypass the target site's host-based authentication and be authorized to perform privileged actions (i.e. actions requiring ALLOW_ADMINISTRATOR or ALLOW_WRITE). Condor deployments using host-based authentication that contain no hostnames (IPs or IP globs only) or use authentication stronger than host-based are not vulnerable.

Alerts:
Red Hat RHSA-2012:1168-01 2012-08-14
Red Hat RHSA-2012:1169-01 2012-08-14
Fedora FEDORA-2012-12127 2012-08-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds