CVE-2011-4930

M

ultiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hold for a job that uses an XML user log, (2) the filename of a file to be transferred, and possibly other unspecified vectors.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:condor_project:condor:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.5:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.4.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.5.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.4:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:1.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:33

Type Values Removed Values Added
References () http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.html - Vendor Advisory () http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0001.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2012-0099.html - () http://rhn.redhat.com/errata/RHSA-2012-0099.html -
References () http://rhn.redhat.com/errata/RHSA-2012-0100.html - () http://rhn.redhat.com/errata/RHSA-2012-0100.html -
References () https://bugzilla.redhat.com/show_bug.cgi?id=759548 - () https://bugzilla.redhat.com/show_bug.cgi?id=759548 -
References () https://htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867 - () https://htcondor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=5e5571d1a431eb3c61977b6dd6ec90186ef79867 -
References () https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264 - () https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28264 -
References () https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429 - () https://htcondor-wiki.cs.wisc.edu/index.cgi/chngview?cn=28429 -
References () https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660 - () https://htcondor-wiki.cs.wisc.edu/index.cgi/tktview?tn=2660 -

Information

Published : 2014-02-10 18:15

Updated : 2025-04-11 00:51


NVD link : CVE-2011-4930

Mitre link : CVE-2011-4930

CVE.ORG link : CVE-2011-4930


JSON object : View

CWE
CWE-134

Use of Externally-Controlled Format String