PT-2020-7219 · Condor · Condor
Florian Weimer
·
Published
2020-01-09
·
Updated
2020-01-29
·
CVE-2012-3490
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Condor versions 7.6.x through 7.6.9
Condor versions 7.8.x through 7.8.3
Description
The my popenv impl and my spawnv functions in src/condor utils/my popen.cpp and the systemCommand function in condor vm-gahp/vmgahp common.cpp do not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Recommendations
For Condor versions 7.6.x through 7.6.9, update to version 7.6.10 or later.
For Condor versions 7.8.x through 7.8.3, update to version 7.8.4 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Condor