PT-2018-6342 · University Of Wisconsin–Madison+1 · Htcondor+1

Brian Bockleman

+2

·

Published

2018-07-05

·

Updated

2021-03-15

·

CVE-2017-16816

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: HTCondor versions 8.6.x through 8.6.7 HTCondor versions 8.7.x through 8.7.4
Description: The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash. This is achieved by leveraging the use of GSI and VOMS extensions in the condor schedd component.
Recommendations: For HTCondor versions 8.6.x through 8.6.7, update to version 8.6.8 or later. For HTCondor versions 8.7.x through 8.7.4, update to version 8.7.5 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16816
USN-4771-1

Affected Products

Htcondor
Ubuntu