CVE-2012-3492
published 2012-09-28CVE-2012-3492: The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when…
PriorityP340medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
3.18%
86.7th percentile
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| debian | condor | < condor 7.8.2~dfsg.1-1+deb7u1 (forky) | condor 7.8.2~dfsg.1-1+deb7u1 (forky) |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
vendor_redhat·2012-09-19·CVSS 6.4
CVE-2012-3492 [MEDIUM] condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
Debian
CVE-2012-3492: condor - The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x bef...
vendor_debian·2012·CVSS 6.4
CVE-2012-3492 [MEDIUM] CVE-2012-3492: condor - The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x bef...
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
Scope: local
forky: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
sid: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
trixie: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
GHSA
GHSA-jf69-6wxx-cpxg: The filesystem authentication (condor_io/condor_auth_fs
ghsa_unreviewed·2022-05-17
CVE-2012-3492 [MEDIUM] CWE-287 GHSA-jf69-6wxx-cpxg: The filesystem authentication (condor_io/condor_auth_fs
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
OSV
CVE-2012-3492: The filesystem authentication (condor_io/condor_auth_fs
osv·2012-09-28·CVSS 6.4
CVE-2012-3492 [MEDIUM] CVE-2012-3492: The filesystem authentication (condor_io/condor_auth_fs
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
bugzilla·2012-09-19·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
bugzilla·2012-08-14·CVSS 6.4
CVE-2012-3492 [MEDIUM] CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
CVE-2012-3492 condor: lock directories created mode 0777 allow for FS-based authentication challenge bypass
Florian Weimer of the Red Hat Product Security Team discovered that Condor's file system authentication challenge accepted directories with weak permissions (for example, world readable, writable and executable permissions). If a user created a directory with such permissions, a local attacker could rename it, allowing them to execute jobs with the privileges of the victim user.
Discussion:
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
---
This issue has been addressed in following products:
MRG for RHEL-5 v. 2
Via RHSA-2012:1278 https://rhn.redhat.com/errata/RHSA-2012-1278.html
---
This issue has been addressed in follo
http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1db67805http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3492http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1db67805http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-3492
2012-09-28
Published