CVE-2011-4930

high

Description

Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

References

https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660

https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429

https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264

https://htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867

https://bugzilla.redhat.com/show_bug.cgi?id=759548

http://rhn.redhat.com/errata/RHSA-2012-0100.html

http://rhn.redhat.com/errata/RHSA-2012-0099.html

http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.html

Details

Source: Mitre, NVD

Published: 2014-02-10

Updated: 2023-02-13

Risk Information

CVSS v2

Base Score: 4.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High