CVE-2009-5136: Input Validation
Published Oct 11, 2013
·Updated
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANTSUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condorstartd exit) via a crafted job.
Affected Software
10 affected components
Condor Project Condor<=7.4.1
Condor Project Condor=7.4.0
redhat Enterprise MRG=1.1.2
redhat Enterprise MRG=1.0.3
redhat Enterprise MRG=1.2.2
redhat Enterprise MRG=1.1.1
redhat Enterprise MRG=1.0
redhat Enterprise MRG=1.0.2
redhat Enterprise MRG=1.0.1
redhat Enterprise MRG=1.2
Event History
Oct 11, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5136?
CVE-2009-5136 has a medium severity rating as it can lead to a denial of service condition.
2
How do I fix CVE-2009-5136?
You can fix CVE-2009-5136 by upgrading Condor to version 7.4.2 or later.
3
Who is affected by CVE-2009-5136?
CVE-2009-5136 affects users of Condor versions prior to 7.4.2 and several versions of Red Hat Enterprise MRG.
4
What type of vulnerability is CVE-2009-5136?
CVE-2009-5136 is a denial of service vulnerability that arises from improper handling of attributes in a policy evaluation.
5
Can unprivileged users exploit CVE-2009-5136?
Yes, remote authenticated users can exploit CVE-2009-5136 to cause a denial of service.