PT-2014-5451 · Adaptive Computing · Torque Resource Manager

Chad Vizino

·

Publicado

2014-10-09

·

Atualizado

2016-12-31

·

CVE-2014-3684

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TORQUE Resource Manager versions 5.0.x, 4.5.x, 4.2.x, and earlier
Description The issue concerns the tm adopt function in the TORQUE Resource Manager, which fails to validate the ownership of the adopted session id. This allows remote authenticated users to kill arbitrary processes by executing a crafted executable.
Recommendations For versions 5.0.x, 4.5.x, 4.2.x, and earlier, consider restricting access to the tm adopt function until a patch is available. As a temporary workaround, limit the execution of crafted executables to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3684
DLA-78-1
DSA-3058-1
MGASA-2014-0408

Produtos afetados

Torque Resource Manager