PT-2013-1376 · Htcondor · Condor

Martin Kudlej

·

Published

2013-10-11

·

Updated

2021-07-15

·

CVE-2009-5136

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Condor versions prior to 7.4.2
Description The policy definition evaluator does not properly handle attributes in a WANT SUSPEND policy that evaluate to an UNDEFINED state. This allows remote authenticated users to cause a denial of service (condor startd exit) via a crafted job.
Recommendations For versions prior to 7.4.2, update to version 7.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the WANT SUSPEND policy to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5136

Affected Products

Condor