CVE-2013-4255

Severity
3.5LOW
EPSS
0.7%
top 27.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 13

Description

The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages3 packages

Debiancondor< 8.0.5~dfsg.1-1+1
NVDredhat/enterprise_mrg4 versions+3

🔴Vulnerability Details

3
GHSA
GHSA-jm9x-cmw2-v945: The policy definition evaluator in Condor 72022-05-13
CVEList
CVE-2013-4255: The policy definition evaluator in Condor 72013-10-11
OSV
CVE-2013-4255: The policy definition evaluator in Condor 72013-10-11

📋Vendor Advisories

2
Red Hat
condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED2013-08-21
Debian
CVE-2013-4255: condor - The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not pro...2013

💬Community

2
Bugzilla
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED [fedora-all]2013-08-21
Bugzilla
CVE-2013-4255 condor: condor_startd DoS when parsing policy definition that evaluates to ERROR or UNDEFINED2013-03-08
CVE-2013-4255 (LOW CVSS 3.5) | The policy definition evaluator in | cvebase.io