CVE-2012-3493
published 2012-09-28CVE-2012-3493: The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain…
PriorityP428medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.67%
74.2th percentile
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| condor_project | condor | >= 0 < 7.8.2~dfsg.1-1+deb7u1 | 7.8.2~dfsg.1-1+deb7u1 |
| debian | condor | < condor 7.8.2~dfsg.1-1+deb7u1 (forky) | condor 7.8.2~dfsg.1-1+deb7u1 (forky) |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: GIVE_REQUEST_AD leaks privileged ClaimId information
vendor_redhat·2012-09-19·CVSS 5.8
CVE-2012-3493 [MEDIUM] condor: GIVE_REQUEST_AD leaks privileged ClaimId information
condor: GIVE_REQUEST_AD leaks privileged ClaimId information
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.
Debian
CVE-2012-3493: condor - The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6....
vendor_debian·2012·CVSS 5.8
CVE-2012-3493 [MEDIUM] CVE-2012-3493: condor - The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6....
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.
Scope: local
forky: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
sid: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
trixie: resolved (fixed in 7.8.2~dfsg.1-1+deb7u1)
GHSA
GHSA-gqg4-4wpq-c69h: The command_give_request_ad function in condor_startd
ghsa_unreviewed·2022-05-17
CVE-2012-3493 [MEDIUM] CWE-200 GHSA-gqg4-4wpq-c69h: The command_give_request_ad function in condor_startd
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.
OSV
CVE-2012-3493: The command_give_request_ad function in condor_startd
osv·2012-09-28·CVSS 5.8
CVE-2012-3493 [MEDIUM] CVE-2012-3493: The command_give_request_ad function in condor_startd
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
bugzilla·2012-09-19·CVSS 4.0
CVE-2012-3491 [MEDIUM] CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
CVE-2012-3491 CVE-2012-3492 CVE-2012-3493 condor various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-3493 condor: GIVE_REQUEST_AD leaks privileged ClaimId information
bugzilla·2012-08-14·CVSS 5.8
CVE-2012-3493 [MEDIUM] CVE-2012-3493 condor: GIVE_REQUEST_AD leaks privileged ClaimId information
CVE-2012-3493 condor: GIVE_REQUEST_AD leaks privileged ClaimId information
Florian Weimer of the Red Hat Product Security Team found that an unauthenticated user able to connect to the Condor startd TCP port could request ads, provided they could guess or brute force the PID of the process, due to how the GIVE_REQUEST_AD handler is registered. The ads contains a lot of already-public information for users with READ privileges, however it also provides the ClaimId (as opposed to the PublicClaimId which truncates the full value of the ClaimID). If an attacker could obtain the private ClaimId, they could use it to control the running job, and also start new jobs on the system.
Discussion:
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=d2f33972http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=848222http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=d2f33972http://research.cs.wisc.edu/condor/manual/v7.6/8_3Stable_Release.htmlhttp://research.cs.wisc.edu/condor/manual/v7.8/9_3Stable_Release.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1278.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1281.htmlhttp://secunia.com/advisories/50666http://www.openwall.com/lists/oss-security/2012/09/20/9http://www.securityfocus.com/bid/55632https://bugzilla.redhat.com/show_bug.cgi?id=848222
2012-09-28
Published