CVE-2017-16816
published 2018-07-05CVE-2017-16816: The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by…
PriorityP427medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.21%
65.0th percentile
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | >= 0 < 8.6.8~dfsg.1-1 | 8.6.8~dfsg.1-1 |
| condor_project | condor | >= 0 < 8.6.8~dfsg.1-1 | 8.6.8~dfsg.1-1 |
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1ubuntu1+esm1 | 8.0.5~dfsg.1-1ubuntu1+esm1 |
| condor_project | condor | >= 0 < 8.4.2~dfsg.1-1ubuntu0.1~esm1 | 8.4.2~dfsg.1-1ubuntu0.1~esm1 |
| debian | condor | < condor 8.6.8~dfsg.1-1 (forky) | condor 8.6.8~dfsg.1-1 (forky) |
| wisc | htcondor | < 8.6.8 | 8.6.8 |
| wisc | htcondor | >= 8.7.0 < 8.7.5 | 8.7.5 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
HTCondor vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 8.8
CVE-2017-16816 [HIGH] HTCondor vulnerabilities
Title: HTCondor vulnerabilities
Summary: Several security issues were fixed in HTCondor.
It was discovered that HTCondor incorrectly invoked the mailx utility. An
attacker could use this vulnerability to execute arbitrary commands. This
issue only affected Ubuntu 14.04 ESM. (CVE-2014-8126)
It was discovered that HTCondor mishandled certain crafted input. An
attacker could use this vulnerability to cause HTCondor to crash.
(CVE-2017-16816)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
condor: DoS of condor_schedd via specially crafted VOMS proxy
vendor_redhat·2017-11-14·CVSS 6.5
CVE-2017-16816 [MEDIUM] CWE-20 condor: DoS of condor_schedd via specially crafted VOMS proxy
condor: DoS of condor_schedd via specially crafted VOMS proxy
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
Statement: Condor in Red Hat Enterprise MRG is built with both GSI and VOMS disabled and therefore is not affected by this issue.
Package: condor (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2017-16816: condor - The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allo...
vendor_debian·2017·CVSS 6.5
CVE-2017-16816 [MEDIUM] CVE-2017-16816: condor - The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allo...
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
Scope: local
forky: resolved (fixed in 8.6.8~dfsg.1-1)
sid: resolved (fixed in 8.6.8~dfsg.1-1)
trixie: resolved (fixed in 8.6.8~dfsg.1-1)
GHSA
GHSA-9x52-5xwr-hfwc: The condor_schedd component in HTCondor before 8
ghsa_unreviewed·2022-05-13
CVE-2017-16816 [MEDIUM] CWE-20 GHSA-9x52-5xwr-hfwc: The condor_schedd component in HTCondor before 8
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
OSV
condor vulnerabilities
osv·2021-03-15·CVSS 8.8
CVE-2014-8126 [HIGH] condor vulnerabilities
condor vulnerabilities
It was discovered that HTCondor incorrectly invoked the mailx utility. An
attacker could use this vulnerability to execute arbitrary commands. This
issue only affected Ubuntu 14.04 ESM. (CVE-2014-8126)
It was discovered that HTCondor mishandled certain crafted input. An
attacker could use this vulnerability to cause HTCondor to crash.
(CVE-2017-16816)
OSV
CVE-2017-16816: The condor_schedd component in HTCondor before 8
osv·2018-07-05·CVSS 6.5
CVE-2017-16816 [MEDIUM] CVE-2017-16816: The condor_schedd component in HTCondor before 8
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [epel-all]
bugzilla·2018-07-06·CVSS 6.5
CVE-2017-16816 [MEDIUM] CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [epel-all]
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [fedora-all]
bugzilla·2018-07-06·CVSS 6.5
CVE-2017-16816 [MEDIUM] CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [fedora-all]
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy
bugzilla·2017-11-02·CVSS 6.5
CVE-2017-16816 [MEDIUM] CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy
CVE-2017-16816 condor: DoS of condor_schedd via specially crafted VOMS proxy
Potential Denial Of Service was discovered wherein an attacker could use a specially-crafted VOMS proxy to crash the condor_schedd.
* If your site is not using GSI authentication, you are not affected. This includes using GSI for authentication with condor, but also allowing users to submit jobs that have the x509UserProxy attribute set.
* If you have disabled VOMS in your condor_config file, you are not affected. VOMS support in HTCondor is *ENABLED* by default.
Discussion:
Acknowledgments:
Name: the HTCondor project
---
Statement:
Condor in Red Hat Enterprise MRG is built with both GSI and VOMS disabled and therefore is not affected by this issue.
---
External Reference:
http://research.cs.wisc.edu/h
http://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2017-0001.htmlhttps://www-auth.cs.wisc.edu/lists/htcondor-users/2017-November/msg00022.shtmlhttp://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2017-0001.htmlhttps://www-auth.cs.wisc.edu/lists/htcondor-users/2017-November/msg00022.shtml
2018-07-05
Published