Vulnerabilities > CVE-2008-3424 - Incorrect Authorization vulnerability in multiple products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family | Fedora Local Security Checks |
NASL id | FEDORA_2008-7205.NASL |
description | A flaw was found in a way condor interpreted wild cards in the authorization lists. Certain authorization lists using wild cards in DENY rules (such as DENY_WRITE or HOSTDENY_WRITE) that conflict with with definitions in ALLOW rule could permit authenticated remote users to submit computation jobs, even when such access should have been denied. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 33883 |
published | 2008-08-14 |
reporter | This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/33883 |
title | Fedora 9 : condor-7.0.4-1.fc9 (2008-7205) |
code |
|
Redhat
advisories |
| ||||||||
rpms |
|
References
- http://secunia.com/advisories/31284
- http://secunia.com/advisories/31284
- http://secunia.com/advisories/31423
- http://secunia.com/advisories/31423
- http://secunia.com/advisories/31459
- http://secunia.com/advisories/31459
- http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4
- http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4
- http://www.redhat.com/support/errata/RHSA-2008-0814.html
- http://www.redhat.com/support/errata/RHSA-2008-0814.html
- http://www.redhat.com/support/errata/RHSA-2008-0816.html
- http://www.redhat.com/support/errata/RHSA-2008-0816.html
- http://www.securityfocus.com/bid/30440
- http://www.securityfocus.com/bid/30440
- http://www.securitytracker.com/id?1020646
- http://www.securitytracker.com/id?1020646
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44063
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44063
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00252.html
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00252.html