CVE-2012-3491
published 2012-09-28CVE-2012-3491: src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote…
PriorityP423medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.83%
76.5th percentile
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| debian | condor | < condor 7.8.2~dfsg.1-1+deb7u1 (forky) | condor 7.8.2~dfsg.1-1+deb7u1 (forky) |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: local users can abort any idle jobs
vendor_redhat·2012-09-19·CVSS 4.0
CVE-2012-3491 [MEDIUM] condor: local users can abort any idle jobs
condor: local users can abort any idle jobs
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Debian
CVE-2012-3491: condor - src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7...
vendor_debian·2012·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491: condor - src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7...
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Scope: local
forky: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
sid: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
trixie: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
GHSA
GHSA-3h4f-jgvh-wjvm: src/condor_schedd
ghsa_unreviewed·2022-05-17
CVE-2012-3491 [MEDIUM] GHSA-3h4f-jgvh-wjvm: src/condor_schedd
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
OSV
CVE-2012-3491: src/condor_schedd
osv·2012-09-28·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491: src/condor_schedd
src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
bugzilla·2012-09-19·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-3491 condor: local users can abort any idle jobs
bugzilla·2012-08-14·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491 condor: local users can abort any idle jobs
CVE-2012-3491 condor: local users can abort any idle jobs
Florian Weimer of the Red Hat Product Security Team discovered that the ability to abort a job in Condor only required WRITE authorization, instead of a combination of WRITE authorization and job ownership. This could allow an authenticated attacker to bypass intended restrictions and abort any idle job on the system.
Discussion:
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
---
This issue has been addressed in following products:
MRG for RHEL-5 v. 2
Via RHSA-2012:1278 https://rhn.redhat.com/errata/RHSA-2012-1278.html
---
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2012:1281 https://rhn.redhat.com/errata/RHSA-2012-1281.html
---
C
http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1fff5d40http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=848214http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1fff5d40http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=848214
2012-09-28
Published