Lucene search

K
cveMitreCVE-2009-2084
HistoryJun 16, 2009 - 11:30 p.m.

CVE-2009-2084

2009-06-1623:30:00
CWE-255
mitre
web.nvd.nist.gov
39
cve-2009-2084
slurm
linux
resource management
vulnerability
privilege escalation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

26.7%

Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the slurmctld daemon, which might allow local SLURM users to modify files and gain privileges.

Affected configurations

Nvd
Node
llnlslurmRange1.3.13
OR
llnlslurmMatch1.2
OR
llnlslurmMatch1.3
OR
llnlslurmMatch1.3.1
OR
llnlslurmMatch1.3.2
OR
llnlslurmMatch1.3.3
OR
llnlslurmMatch1.3.4
OR
llnlslurmMatch1.3.5
OR
llnlslurmMatch1.3.6
OR
llnlslurmMatch1.3.7
OR
llnlslurmMatch1.3.8
OR
llnlslurmMatch1.3.9
OR
llnlslurmMatch1.3.10
OR
llnlslurmMatch1.3.11
OR
llnlslurmMatch1.3.12
VendorProductVersionCPE
llnlslurm*cpe:2.3:a:llnl:slurm:*:*:*:*:*:*:*:*
llnlslurm1.2cpe:2.3:a:llnl:slurm:1.2:*:*:*:*:*:*:*
llnlslurm1.3cpe:2.3:a:llnl:slurm:1.3:*:*:*:*:*:*:*
llnlslurm1.3.1cpe:2.3:a:llnl:slurm:1.3.1:*:*:*:*:*:*:*
llnlslurm1.3.2cpe:2.3:a:llnl:slurm:1.3.2:*:*:*:*:*:*:*
llnlslurm1.3.3cpe:2.3:a:llnl:slurm:1.3.3:*:*:*:*:*:*:*
llnlslurm1.3.4cpe:2.3:a:llnl:slurm:1.3.4:*:*:*:*:*:*:*
llnlslurm1.3.5cpe:2.3:a:llnl:slurm:1.3.5:*:*:*:*:*:*:*
llnlslurm1.3.6cpe:2.3:a:llnl:slurm:1.3.6:*:*:*:*:*:*:*
llnlslurm1.3.7cpe:2.3:a:llnl:slurm:1.3.7:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

26.7%