PT-2011-3675 · Adaptive Computing · Torque Resource Manager
Published
2011-06-24
·
Updated
2018-10-09
·
CVE-2011-2193
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TORQUE Resource Manager versions 2.x through 2.4.13
TORQUE Resource Manager versions 2.5.x through 2.5.5
TORQUE Resource Manager versions 3.x through 3.0.1
Description
The issue concerns buffer overflows in the TORQUE Resource Manager. Remote authenticated users may gain privileges by submitting a qsub command with a long
Job Name field to the server. Additionally, local users might gain privileges through vectors involving a long host variable in pbs iff.Recommendations
For versions 2.x through 2.4.13, update to version 2.4.14 or later.
For versions 2.5.x through 2.5.5, update to version 2.5.6 or later.
For versions 3.x through 3.0.1, update to version 3.0.2 or later.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Torque Resource Manager