CVE-2013-4255
published 2013-10-11CVE-2013-4255: The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4)…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.64%
73.8th percentile
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | <= 8.0.0 | — |
| condor_project | condor | — | — |
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1 | 8.0.5~dfsg.1-1 |
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1 | 8.0.5~dfsg.1-1 |
| debian | condor | < condor 8.0.5~dfsg.1-1 (forky) | condor 8.0.5~dfsg.1-1 (forky) |
| redhat | enterprise_mrg | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | enterprise_mrg | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
vendor_redhat·2013-08-21·CVSS 3.5
CVE-2013-4255 [LOW] condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
Package: condor (Red Hat Enterprise MRG 1) - Will not fix
Debian
CVE-2013-4255: condor - The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not pro...
vendor_debian·2013·CVSS 3.5
CVE-2013-4255 [LOW] CVE-2013-4255: condor - The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not pro...
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
Scope: local
forky: resolved (fixed in 8.0.5~dfsg.1-1)
sid: resolved (fixed in 8.0.5~dfsg.1-1)
trixie: resolved (fixed in 8.0.5~dfsg.1-1)
GHSA
GHSA-jm9x-cmw2-v945: The policy definition evaluator in Condor 7
ghsa_unreviewed·2022-05-13
CVE-2013-4255 [LOW] CWE-20 GHSA-jm9x-cmw2-v945: The policy definition evaluator in Condor 7
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
OSV
CVE-2013-4255: The policy definition evaluator in Condor 7
osv·2013-10-11·CVSS 3.5
CVE-2013-4255 [LOW] CVE-2013-4255: The policy definition evaluator in Condor 7
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED [fedora-all]
bugzilla·2013-08-21·CVSS 3.5
CVE-2013-4255 [LOW] CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED [fedora-all]
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field w
Bugzilla
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
bugzilla·2013-03-08·CVSS 3.5
CVE-2013-4255 [LOW] CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED
A denial of service flaw was found in the way Condor's policy definition evaluator processed certain policy definitions. If an administrator used an attribute defined on a job in any of the following condor_startd policies (CONTINUE, KILL, PREEMPT, SUSPEND), a remote Condor service user could use this flaw to cause a denial of the condor_startd service by submitting a Condor job that caused certain policy definition to be evaluated to either ERROR or UNDEFINED states.
Workaround:
Check for UNDEFINED & ERROR in the policy configuration.
Discussion:
Acknowledgements:
This issue was found by Matthew Farrellee of Red Hat.
---
Upstream pointed out that this issue is known with seve
http://rhn.redhat.com/errata/RHSA-2013-1171.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1172.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=919401https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1786https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=3829http://rhn.redhat.com/errata/RHSA-2013-1171.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1172.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=919401https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1786https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=3829
2013-10-11
Published