cbcvebase.
CVE-2012-3491
published 2012-09-28

CVE-2012-3491: src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote…

medium4CVSS 3.1
AVNACLAuSCNINAP
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.

Affected

17 ranges
VendorProductVersion rangeFixed in
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor>= 0 < 7.8.2~dfsg.1-1+deb7u17.8.2~dfsg.1-1+deb7u1
condor_projectcondor>= 0 < 7.8.2~dfsg.1-1+deb7u17.8.2~dfsg.1-1+deb7u1
debiancondor< condor 7.8.2~dfsg.1-1+deb7u1 (forky)condor 7.8.2~dfsg.1-1+deb7u1 (forky)

CVSS provenance

nvd4.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM