Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101675 | vdb entry third party advisory |
https://www.schedmd.com/news.php?id=193#OPT_193 | vendor advisory |
https://www.debian.org/security/2017/dsa-4023 | third party advisory vendor advisory |