CVE-2012-3416
published 2012-08-25CVE-2012-3416: Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting…
PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.10%
91.4th percentile
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | <= 7.8.1 | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: host based authentication does not implement forward-confirmed reverse dns
vendor_redhat·2012-08-14·CVSS 10.0
CVE-2012-3416 [CRITICAL] CWE-284 condor: host based authentication does not implement forward-confirmed reverse dns
condor: host based authentication does not implement forward-confirmed reverse dns
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
Package: condor (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2012-3416: condor - Condor before 7.8.2 allows remote attackers to bypass host-based authentication ...
vendor_debian·2012·CVSS 10.0
CVE-2012-3416 [CRITICAL] CVE-2012-3416: condor - Condor before 7.8.2 allows remote attackers to bypass host-based authentication ...
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
Scope: local
forky: resolved (fixed in 7.8.2~dfsg.1-1)
sid: resolved (fixed in 7.8.2~dfsg.1-1)
trixie: resolved (fixed in 7.8.2~dfsg.1-1)
GHSA
GHSA-g6rg-4rx4-gw4m: Condor before 7
ghsa_unreviewed·2022-05-17
CVE-2012-3416 [HIGH] CWE-287 GHSA-g6rg-4rx4-gw4m: Condor before 7
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
OSV
CVE-2012-3416: Condor before 7
osv·2012-08-25·CVSS 10.0
CVE-2012-3416 [CRITICAL] CVE-2012-3416: Condor before 7
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
Suricata
ET WEB_SERVER ASP.NET Forms Authentication Bypass
suricata·2012-01-03
CVE-2011-3416 ET WEB_SERVER ASP.NET Forms Authentication Bypass
ET WEB_SERVER ASP.NET Forms Authentication Bypass
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER ASP.NET Forms Authentication Bypass"; flow:established,to_server; http.uri; content:"/CreatingUserAccounts.aspx"; fast_pattern; http.request_body; content:"CreateUserStepContainer"; content:"UserName="; distance:0; content:"%00"; distance:0; pcre:"/UserName\x3d[^\x26]+\x2500/"; reference:cve,2011-3416; classtype:attempted-user; sid:2014100; rev:7; metadata:created_at 2012_01_03, cve CVE_2011_3416, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Pub
No public exploits indexed.
Bugzilla
CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns [fedora-all]
bugzilla·2012-08-14·CVSS 10.0
CVE-2012-3416 [CRITICAL] CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns [fedora-all]
CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproje
Bugzilla
CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns
bugzilla·2012-07-18·CVSS 10.0
CVE-2012-3416 [CRITICAL] CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns
CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns
Condor installations that rely solely upon host-based authentication are vulnerable to an attacker who controls an IP, its reverse-DNS entry and has knowledge of a target site's security configuration. With this control and knowledge, the attacker can bypass the target site's host-based authentication and be authorized to perform privileged actions (i.e. actions requiring ALLOW_ADMINISTRATOR or ALLOW_WRITE). Condor deployments using host-based authentication that contain no hostnames (IPs or IP globs only) or use authentication stronger than host-based are not vulnerable.
Discussion:
Acknowledgements:
Red Hat would like to thank Ken Hahn and Dan Bradley for reporting this issue.
---
This
http://osvdb.org/84766http://research.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2012-0002.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1168.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1169.htmlhttp://secunia.com/advisories/50246http://secunia.com/advisories/50294http://www.securityfocus.com/bid/55032http://www.securitytracker.com/id?1027395https://exchange.xforce.ibmcloud.com/vulnerabilities/77748http://osvdb.org/84766http://research.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2012-0002.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1168.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1169.htmlhttp://secunia.com/advisories/50246http://secunia.com/advisories/50294http://www.securityfocus.com/bid/55032http://www.securitytracker.com/id?1027395https://exchange.xforce.ibmcloud.com/vulnerabilities/77748
2012-08-25
Published