Secunia Logo  
 
CVE Reference: CVE-2008-3424
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-3424

Description:
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/44063

ST
  1020646

SAID
  Secunia Advisory: SA31284
  Secunia Advisory: SA31459
  Secunia Advisory: SA31423

REDHAT
  http://www.redhat.com/support/errata/RHSA-2008-0814.html
  http://www.redhat.com/support/errata/RHSA-2008-0816.html

FEDORA

CONFIRM
  http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4

BID
  30440


Return to the previous page.