CVE-2012-5390
published 2014-06-06CVE-2012-5390: The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.49%
82.8th percentile
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1ubuntu1 | 8.0.5~dfsg.1-1ubuntu1 |
| debian | condor | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0LOW
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: privilege escalation via jobs submitted to the standard universe (CONDOR-2012-0003)
vendor_redhat·2012-10-22·CVSS 10.0
CVE-2012-5390 [CRITICAL] condor: privilege escalation via jobs submitted to the standard universe (CONDOR-2012-0003)
condor: privilege escalation via jobs submitted to the standard universe (CONDOR-2012-0003)
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
Statement: Not vulnerable. This issue did not affect the versions of condor as shipped with Red Hat Enterprise MRG 1 or 2 as they do not provide a vulnerable version of condor.
Package: condor (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2012-5390: condor - The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 throu...
vendor_debian·2012·CVSS 10.0
CVE-2012-5390 [CRITICAL] CVE-2012-5390: condor - The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 throu...
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-wmv8-6jgv-xfr2: The standard universe shadow (condor_shadow
ghsa_unreviewed·2022-05-17
CVE-2012-5390 [HIGH] GHSA-wmv8-6jgv-xfr2: The standard universe shadow (condor_shadow
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
OSV
CVE-2012-5390: The standard universe shadow (condor_shadow
osv·2014-06-06·CVSS 10.0
CVE-2012-5390 [CRITICAL] CVE-2012-5390: The standard universe shadow (condor_shadow
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
No detection rules found.
No public exploits indexed.
http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0003.htmlhttp://secunia.com/advisories/51862http://www.securityfocus.com/bid/57328http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0003.htmlhttp://secunia.com/advisories/51862http://www.securityfocus.com/bid/57328
2014-06-06
Published