PT-2002-1093 · Nqe · Nqe+2

Published

2002-01-31

·

Updated

2017-10-10

·

CVE-2001-0891

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NQE version 3.3.0.16
Description A format string issue in the NQS daemon (nqsdaemon) allows a local user to gain root privileges. This can be achieved by submitting a batch job with a name that contains formatting characters using qsub.
Recommendations For NQE version 3.3.0.16, consider restricting access to the qsub command to prevent submission of batch jobs with malicious names until a fix is available. As a temporary workaround, avoid using formatting characters in batch job names to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0891

Affected Products

Nqe
Nqsdaemon
Qsub