LWN.net Logo

MRG Grid: denial of service

Package(s):MRG Grid CVE #(s):CVE-2012-4462
Created:March 7, 2013 Updated:March 13, 2013
Description:

From the Red Hat advisory:

It was found that attempting to remove a job via "/usr/share/condor/aviary/jobcontrol.py" with CPROC in square brackets caused condor_schedd to crash. If aviary_query_server was configured to listen to public interfaces, this could allow a remote attacker to cause a denial of service condition in condor_schedd. While condor_schedd was restarted by the condor_master process after each exit, condor_master would throttle back restarts after each crash. This would slowly increment to the defined MASTER_BACKOFF_CEILING value (3600 seconds/1 hour, by default). (CVE-2012-4462)

Alerts:
Red Hat RHSA-2013:0564-01 2013-03-06
Red Hat RHSA-2013:0565-01 2013-03-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds