The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0003.html | vendor advisory |
http://www.securityfocus.com/bid/57328 | vdb entry |
http://secunia.com/advisories/51862 | third party advisory |