CVE-2012-3490XML External Entity (XXE) Injection in Condor

Severity
8.8HIGHNVD
GHSA5.0
EPSS
1.9%
top 16.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 9
Latest updateMay 14

Description

The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

NVDwisc/htcondor7.6.07.6.10+1
Debiancondor_project/condor< 7.8.2~dfsg.1-1+deb7u1+1
CVEListV5condor/condor7.6.x before 7.6.10 and 7.8.x before 7.8.4

🔴Vulnerability Details

4
GHSA
Incorrect Privilege Assignment in RESTEasy2022-05-14
GHSA
GHSA-p9fv-x796-2hrm: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen2022-04-23
CVEList
CVE-2012-3490: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen2020-01-09
OSV
CVE-2012-3490: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen2020-01-09

📋Vendor Advisories

4
Red Hat
RESTEasy: XXE via parameter entities2014-07-23
Red Hat
condor: does not check return value of setuid and similar calls, exploitable via VMware support2012-09-19
Red Hat
condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)2012-09-19
Debian
CVE-2012-3490: condor - The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen....2012

💬Community

2
Bugzilla
CVE-2012-5197 condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)2012-10-24
Bugzilla
CVE-2012-3490 condor: does not check return value of setuid and similar calls, exploitable via VMware support2012-08-14
CVE-2012-3490 — XML External Entity (XXE) Injection | cvebase