Condor Authorization List Bug May Let Remote Users Bypass Access Controls
|
|
SecurityTracker Alert ID: 1020646 |
|
SecurityTracker URL: http://securitytracker.com/id/1020646
|
|
CVE Reference:
CVE-2008-3424
(Links to External Site)
|
Date: Aug 11 2008
|
Impact:
Host/resource access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): prior to 7.0.4
|
Description:
A vulnerability was reported in Condor. A remote user may be able to bypass access controls.
The software does not properly process wild card characters in authorization lists. If the system has a configuration variable that specifies the policy and contains the wild card asterisk character, a user may be able to access the system.
Affected variables include ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, and HOSTDENY_WRITE.
|
Impact:
A remote user may be able to bypass access controls and access the target system.
|
Solution:
The vendor has issued a fixed version (7.0.4), available at:
http://www.cs.wisc.edu/condor/downloads-v2/download.pl
|
Vendor URL: www.cs.wisc.edu/condor/ (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 23 Jul 2008 14:05:39 -0500
Subject: [Condor-world] Condor 7.0.4 released
|
The Condor Team is pleased to announce the release of Condor 7.0.4. This
release fixes a problem with DENY lists in the authorization policy that
could allow access when it should be denied. Additional changes include
guarding against administrative tools cleaning up in-use files in the
system's temporary directory and improving memory usage in the
collector. Bugs fixed on Windows include daemons failing to start and
crashes related to Condor-C and parallel jobs. See the version history
for a complete list of bugs that have been fixed. Condor 7.0.4 binaries
and source code are available from our downloads page.
Version History:
http://www.cs.wisc.edu/condor/manual/ v7.0/8_3Stable_Release.html#sec:New-7-0-4
Downloads Page:
http://www.cs.wisc.edu/condor/downloads
Enjoy!
|
|