cbcvebase.
CVE-2012-3492
published 2012-09-28

CVE-2012-3492: The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when…

PriorityP340medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
3.18%
86.7th percentile
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.

Affected

17 ranges
VendorProductVersion rangeFixed in
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor
condor_projectcondor>= 0 < 7.8.2~dfsg.1-1+deb7u17.8.2~dfsg.1-1+deb7u1
condor_projectcondor>= 0 < 7.8.2~dfsg.1-1+deb7u17.8.2~dfsg.1-1+deb7u1
debiancondor< condor 7.8.2~dfsg.1-1+deb7u1 (forky)condor 7.8.2~dfsg.1-1+deb7u1 (forky)

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.