Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://openwall.com/lists/oss-security/2012/01/05/1 | mailing list |
http://secunia.com/advisories/47381 | third party advisory vendor advisory |
http://openwall.com/lists/oss-security/2012/01/05/9 | mailing list patch |
http://www.adaptivecomputing.com/resources/docs/torque/3-0-3/changelog.php#259 | |
http://www.securityfocus.com/bid/51224 | vdb entry |