First published: Thu Mar 18 2004(Updated: )
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Platform LSF | =5.1 | |
IBM Platform LSF | =4.0 | |
IBM Platform LSF | =5.0 | |
IBM Platform LSF | =4.2 | |
IBM Platform LSF | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0318 is classified as a high-severity vulnerability due to its potential to allow privilege escalation.
To fix CVE-2004-0318, it is recommended to upgrade to a patched version of IBM Platform LSF that does not utilize the LSF_EAUTH_UID environment variable.
CVE-2004-0318 affects users of IBM Platform LSF versions 4.x, 5.x, and 6.x that have the LSF_EAUTH_UID environment variable set.
If exploited, CVE-2004-0318 could allow remote attackers within the local cluster to gain unauthorized privileges.
A possible workaround for CVE-2004-0318 includes disabling the use of the LSF_EAUTH_UID environment variable if feasible.