PT-2020-7219 · Condor · Condor

Florian Weimer

·

Published

2020-01-09

·

Updated

2020-01-29

·

CVE-2012-3490

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Condor versions 7.6.x through 7.6.9 Condor versions 7.8.x through 7.8.3
Description The my popenv impl and my spawnv functions in src/condor utils/my popen.cpp and the systemCommand function in condor vm-gahp/vmgahp common.cpp do not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Recommendations For Condor versions 7.6.x through 7.6.9, update to version 7.6.10 or later. For Condor versions 7.8.x through 7.8.3, update to version 7.8.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-3490

Affected Products

Condor