Lucene search

K
redhatRedHatRHSA-2009:1689
HistoryDec 21, 2009 - 12:00 a.m.

(RHSA-2009:1689) Moderate: condor security update

2009-12-2100:00:00
access.redhat.com
6

0.005 Low

EPSS

Percentile

75.9%

Condor is a specialized workload management system for compute-intensive
jobs. It provides a job queuing mechanism, scheduling policy, priority
scheme, and resource monitoring and management.

A flaw was found in the way Condor managed jobs. This could allow a user
that is authorized to submit jobs into Condor to queue a job as if it were
submitted by a different local user, potentially leading to unauthorized
access to that userโ€™s account. (CVE-2009-4133)

Note: Condor will not run jobs as root; therefore, this flaw cannot lead to
a compromise of the root user account.

All Red Hat Enterprise MRG 1.2 users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.
Condor must be restarted for the update to take effect.