what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 3149-1

Debian Security Advisory 3149-1
Posted Feb 2, 2015
Authored by Debian | Site debian.org

Debian Linux Security Advisory 3149-1 - Florian Weimer, of Red Hat Product Security, discovered an issue in condor, a distributed workload management system. Upon job completion, it can optionally notify a user by sending an email; the mailx invocation used in that process allowed for any authenticated user able to submit jobs, to execute arbitrary code with the privileges of the condor user.

tags | advisory, arbitrary
systems | linux, redhat, debian
advisories | CVE-2014-8126
SHA-256 | d67dc19e1a51dcc33a68b430ffc86de24f5824b229425ade21a664c4eb4718b1

Debian Security Advisory 3149-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3149-1 security@debian.org
http://www.debian.org/security/ Sebastien Delafond
February 02, 2015 http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : condor
CVE ID : CVE-2014-8126
Debian Bug : 775276

Florian Weimer, of Red Hat Product Security, discovered an issue in
condor, a distributed workload management system. Upon job completion,
it can optionally notify a user by sending an email; the mailx
invocation used in that process allowed for any authenticated user
able to submit jobs, to execute arbitrary code with the privileges of
the condor user.

For the stable distribution (wheezy), this problem has been fixed in
version 7.8.2~dfsg.1-1+deb7u3.

For the upcoming stable distribution (jessie) and unstable
distribution (sid), this problem has been fixed in version
8.2.3~dfsg.1-6.

We recommend that you upgrade your condor packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJUz70nAAoJEBC+iYPz1Z1kCqQH/1xCvdVHtd2cJnt+Y4iYKuvL
l2y1F220MQKr0idmbMfFoGOcLloawHguuKV9aVzpF8ONLA4SKT0glegSOQ/Q4w3U
V2qoi/pXUT2HTSHQkQZfJnOOR8dR7QN7UR2XfAfoCq+rpp5wP/rqth4y/SxwSGQF
B5bnkmfyXiThCCW2rs5V6Y8eBYc/4gPzFA4b9M5tPZ0YhKWF93R7YvYKeKgFaFGB
iTgWu4ldNSlY+5jvGEYe8aar2J9F4SCHAh5W66G2bJLiEjmlNe5hQGy+baZJUA/g
LyVtXG3oodis+qxi3DEBscdRSkkkf0LC8xqvHIiBD7Yz/dLKrHm/ju4IlkzXols=
=RLVq
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

August 2022

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    20 Files
  • 2
    Aug 2nd
    4 Files
  • 3
    Aug 3rd
    6 Files
  • 4
    Aug 4th
    55 Files
  • 5
    Aug 5th
    16 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    13 Files
  • 9
    Aug 9th
    13 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close