PT-2002-1093 · Nqe · Nqe+2
Published
2002-01-31
·
Updated
2017-10-10
·
CVE-2001-0891
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NQE version 3.3.0.16
Description
A format string issue in the NQS daemon (nqsdaemon) allows a local user to gain root privileges. This can be achieved by submitting a batch job with a name that contains formatting characters using qsub.
Recommendations
For NQE version 3.3.0.16, consider restricting access to the qsub command to prevent submission of batch jobs with malicious names until a fix is available. As a temporary workaround, avoid using formatting characters in batch job names to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nqe
Nqsdaemon
Qsub