Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-3493
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-3493

2022-10-0316:15:21
Debian Security Bug Tracker
security-tracker.debian.org
11
condor
command_give_request_ad
vulnerability
information leakage
remote attack
sensitive information
arbitrary jobs
classad request
condor_startd
claimid
unix

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

72.9%

The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.

OSVersionArchitecturePackageVersionFilename
Debian999allcondor< 7.8.2~dfsg.1-1+deb7u1condor_7.8.2~dfsg.1-1+deb7u1_all.deb

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

0.004 Low

EPSS

Percentile

72.9%