PT-2012-4757 · Htcondor · Condor

Florian Weimer

·

Published

2012-09-28

·

Updated

2012-10-03

·

CVE-2012-3492

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Condor versions 7.6.x through 7.6.9 Condor versions 7.8.x through 7.8.3
Description The issue concerns the filesystem authentication in Condor, where authentication directories with weak permissions are used. This allows remote attackers to impersonate users by renaming a user's authentication directory.
Recommendations For Condor versions 7.6.x through 7.6.9, update to version 7.6.10 or later. For Condor versions 7.8.x through 7.8.3, update to version 7.8.4 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3492
RHSA-2012:1278
RHSA-2012:1281

Affected Products

Condor