CVE-2017-16816
published 2018-07-05CVE-2017-16816: The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by…
medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | >= 0 < 8.6.8~dfsg.1-1 | 8.6.8~dfsg.1-1 |
| condor_project | condor | >= 0 < 8.6.8~dfsg.1-1 | 8.6.8~dfsg.1-1 |
| condor_project | condor | >= 0 < 8.0.5~dfsg.1-1ubuntu1+esm1 | 8.0.5~dfsg.1-1ubuntu1+esm1 |
| condor_project | condor | >= 0 < 8.4.2~dfsg.1-1ubuntu0.1~esm1 | 8.4.2~dfsg.1-1ubuntu0.1~esm1 |
| debian | condor | < condor 8.6.8~dfsg.1-1 (forky) | condor 8.6.8~dfsg.1-1 (forky) |
| wisc | htcondor | < 8.6.8 | 8.6.8 |
| wisc | htcondor | >= 8.7.0 < 8.7.5 | 8.7.5 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH