Sign in
CVE-2009-5136
CVE-2009-5136
Description
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
Impact
CVSS v2 : 4 MEDIUM
Type
CWE-20
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:S/C:N/I:N/A:P
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
https://bugzilla.redhat.com/show_bug.cgi?id=540545
https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1001
http://research.cs.wisc.edu/htcondor/manual/v7.6/8_5Stable_Release.html
http://rhn.redhat.com/errata/RHSA-2010-0773.html
FAQ
Terms of service
Privacy policy