PT-2003-1541 · Ibm · Lsf
Tomasz Grabowski
·
Publicado
2003-05-22
·
Atualizado
2016-10-18
·
CVE-2003-0337
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
LSF version 5.1
Description:
The issue allows local users to execute arbitrary programs. This is achieved by modifying the
LSF ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF SERVERDIR to point to a malicious lim program, which lsadmin then executes.Recommendations:
For LSF version 5.1, restrict access to the
LSF ENVDIR and LSF SERVERDIR environment variables to prevent modification by unauthorized users. As a temporary workaround, consider disabling the execution of the lim program by lsadmin until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lsf