CVE-2011-4930
published 2014-02-10CVE-2011-4930: Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other…
PriorityP420medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.59%
44.1th percentile
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| debian | condor | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xf2q-8pgg-943r: Multiple format string vulnerabilities in Condor 7
ghsa_unreviewed·2022-05-13
CVE-2011-4930 [MEDIUM] CWE-134 GHSA-xf2q-8pgg-943r: Multiple format string vulnerabilities in Condor 7
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.
Red Hat
Condor: Multiple format string flaws
vendor_redhat·2012-02-06·CVSS 4.4
CVE-2011-4930 [MEDIUM] Condor: Multiple format string flaws
Condor: Multiple format string flaws
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.
Package: grid-condor (Red Hat Enterprise MRG 1) - Affected
Debian
CVE-2011-4930: condor - Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possib...
vendor_debian·2011·CVSS 4.4
CVE-2011-4930 [MEDIUM] CVE-2011-4930: condor - Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possib...
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4930 Condor: Multiple format string flaws [fedora-all]
bugzilla·2012-02-06·CVSS 4.4
CVE-2011-4930 [MEDIUM] CVE-2011-4930 Condor: Multiple format string flaws [fedora-all]
CVE-2011-4930 Condor: Multiple format string flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=759548
Bugzilla
CVE-2011-4930 Condor: Multiple format string flaws
bugzilla·2011-12-02·CVSS 4.4
CVE-2011-4930 [MEDIUM] CVE-2011-4930 Condor: Multiple format string flaws
CVE-2011-4930 Condor: Multiple format string flaws
Multiple format string flaws were found in Condor:
a) when the XML message log format was requested in Condor submit job by remote Condor user and that user attempted to write a specially-crafted message into user log file via condor_hold tool it could lead to condor_schedd daemon crash, or, potentially arbitrary code execution with the privileges of the 'condor' user [*]. Also this way an attacker could potentially prevent other Condor jobs from being scheduled and ever executed,
b) request for file transfer by remote Condor user to transmit a file, with specially-crafted name, could lead to child process of condor_schedd daemon to crash (repeated process, where condor_schedd daemon would fork a child process to handle the request, the
http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0099.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0100.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=759548https://htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0099.htmlhttp://rhn.redhat.com/errata/RHSA-2012-0100.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=759548https://htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660
2014-02-10
Published