CVE-2008-3830
published 2008-10-08CVE-2008-3830: Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.39%
31.1th percentile
Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | <= 7.0.4 | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| debian | condor | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: allow or deny with overlapping netmasks may be ignored
vendor_redhat·2008-10-07·CVSS 7.2
CVE-2008-3830 [HIGH] condor: allow or deny with overlapping netmasks may be ignored
condor: allow or deny with overlapping netmasks may be ignored
Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.
Debian
CVE-2008-3830: condor - Condor before 7.0.5 does not properly handle when the configuration specifies ov...
vendor_debian·2008·CVSS 7.2
CVE-2008-3830 [HIGH] CVE-2008-3830: condor - Condor before 7.0.5 does not properly handle when the configuration specifies ov...
Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-x3pw-4w9m-43c6: Condor before 7
ghsa_unreviewed·2022-05-02
CVE-2008-3830 [HIGH] GHSA-x3pw-4w9m-43c6: Condor before 7
Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.
No detection rules found.
http://secunia.com/advisories/32189http://secunia.com/advisories/32193http://secunia.com/advisories/32232http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000http://www.redhat.com/support/errata/RHSA-2008-0911.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0924.htmlhttp://www.securityfocus.com/bid/31621http://www.securitytracker.com/id?1021002http://www.vupen.com/english/advisories/2008/2760https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00264.htmlhttp://secunia.com/advisories/32189http://secunia.com/advisories/32193http://secunia.com/advisories/32232http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000http://www.redhat.com/support/errata/RHSA-2008-0911.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0924.htmlhttp://www.securityfocus.com/bid/31621http://www.securitytracker.com/id?1021002http://www.vupen.com/english/advisories/2008/2760https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00264.html
2008-10-08
Published