CVE-2012-3490
published 2020-01-09CVE-2012-3490: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.57%
88.1th percentile
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor | condor | — | — |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| debian | condor | < condor 7.8.2~dfsg.1-1+deb7u1 (forky) | condor 7.8.2~dfsg.1-1+deb7u1 (forky) |
| wisc | htcondor | >= 7.6.0 < 7.6.10 | 7.6.10 |
| wisc | htcondor | >= 7.8.0 < 7.8.4 | 7.8.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa5.0MEDIUM
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Incorrect Privilege Assignment in RESTEasy
ghsa·2022-05-14·CVSS 5.0
CVE-2014-3490 [MEDIUM] CWE-266 Incorrect Privilege Assignment in RESTEasy
Incorrect Privilege Assignment in RESTEasy
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
GHSA
GHSA-p9fv-x796-2hrm: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen
ghsa_unreviewed·2022-04-23
CVE-2012-3490 [HIGH] GHSA-p9fv-x796-2hrm: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
OSV
CVE-2012-3490: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen
osv·2020-01-09·CVSS 8.8
CVE-2012-3490 [HIGH] CVE-2012-3490: The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Red Hat
RESTEasy: XXE via parameter entities
vendor_redhat·2014-07-23·CVSS 5.0
CVE-2014-3490 [MEDIUM] CWE-611 RESTEasy: XXE via parameter entities
RESTEasy: XXE via parameter entities
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.
It was found that the fix for CVE-2012-0818 was incomplete: external parameter entities were not disabled when the resteasy.document.expand.entity.references parameter was set to false. A remote attacker able to send XML requests to a RESTEasy endpoint could use this flaw to read fi
Red Hat
condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
vendor_redhat·2012-09-19·CVSS 8.8
CVE-2012-5197 [HIGH] condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors related to "error checking of system calls."
Statement: Not vulnerable. This issue did not affect the versions of condor as shipped with Red Hat Enterprise MRG as it does not include the vulnerable code (VMware support is not compiled in).
Package: condor (Red Hat Enterprise MRG 1) - Will not fix
Package: condor (Red Hat Enterprise MRG 2) - Not affected
Red Hat
condor: does not check return value of setuid and similar calls, exploitable via VMware support
vendor_redhat·2012-09-19·CVSS 8.8
CVE-2012-3490 [HIGH] condor: does not check return value of setuid and similar calls, exploitable via VMware support
condor: does not check return value of setuid and similar calls, exploitable via VMware support
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Statement: Not vulnerable. This issue did not affect the versions of condor as shipped with Red Hat Enterprise MRG as it does not include the vulnerable code (VMware support is not compiled in).
Package: condor (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2012-3490: condor - The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen....
vendor_debian·2012·CVSS 8.8
CVE-2012-3490 [HIGH] CVE-2012-3490: condor - The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen....
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
Scope: local
forky: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
sid: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
trixie: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5197 condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
bugzilla·2012-10-24·CVSS 8.8
CVE-2012-5197 [HIGH] CVE-2012-5197 condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
CVE-2012-5197 condor: multiple unspecified vulnerabilities (likely a duplicate of CVE-2012-3490)
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-5197 to
the following vulnerability:
Name: CVE-2012-5197
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5197
Assigned: 20120928
Reference: http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.html
Reference: http://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.html
Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and
7.8.x before 7.8.4 have unknown impact and attack vectors related to
"error checking of system calls."
These issues were noted in the release notes to have no security impact:
* Security Item: Although not user-visible, there were updates to the code to
Bugzilla
CVE-2012-3490 condor: does not check return value of setuid and similar calls, exploitable via VMware support
bugzilla·2012-08-14·CVSS 8.8
CVE-2012-3490 [HIGH] CVE-2012-3490 condor: does not check return value of setuid and similar calls, exploitable via VMware support
CVE-2012-3490 condor: does not check return value of setuid and similar calls, exploitable via VMware support
Florian Weimer of the Red Hat Product Security Team reported that certain functions in Condor (my_popenv_impl and my_spawnv in src/condor_utils/my_popen.cpp) did not check the return value of setuid and similar function calls:
* euid = geteuid();
* egid = getegid();
* seteuid( 0 );
* setgroups( 1, &egid );
* setgid( egid );
* setuid( euid );
As a result, the subprocess could possibly be created with root privileges instead of those of the intended user.
Discussion:
Sorry, I had missed your question. See my last comment on the original bug:
I tried to come up with a scenario in which a UID transition does actually occur, and failed. I don't think anymore this is a security iss
http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=94e84ce4http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://www.openwall.com/lists/oss-security/2012/09/20/9https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3490http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=94e84ce4http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://www.openwall.com/lists/oss-security/2012/09/20/9https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3490
2020-01-09
Published