Multiple format string vulnerabilities in Condor is vulnerable to denial of service (DoS). Due to a flaw, an authenticated Condor service user can prevent other jobs from being scheduled and executed, crash the condor_schedd daemon, or, possibly, execute arbitrary code with the privileges of the “condor” user.
research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.html
rhn.redhat.com/errata/RHSA-2012-0099.html
rhn.redhat.com/errata/RHSA-2012-0100.html
access.redhat.com/errata/RHSA-2012:0100
access.redhat.com/security/updates/classification/#moderate
bugzilla.redhat.com/show_bug.cgi?id=759548
docs.redhat.com/docs/en-US/Red_Hat_Enterprise_MRG/2/html/Technical_Notes/index.html
htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867
htcondor-git.cs.wisc.edu/?p=condor.git;a=commitdiff;h=5e5571d1a431eb3c61977b6dd6ec90186ef79867
htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264
htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429
htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660