CVE-2012-3492: Medium severity htcondor vulnerability
The filesystem authentication (condorio/condorauthfs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a user's authentication directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3492?
CVE-2012-3492 is considered a medium severity vulnerability due to the potential for user impersonation.
How do I fix CVE-2012-3492?
To fix CVE-2012-3492, upgrade to Condor version 7.6.10 or 7.8.4 or later.
What versions are affected by CVE-2012-3492?
CVE-2012-3492 affects Condor versions 7.6.0 through 7.6.9 and 7.8.0 through 7.8.3.
What type of attack does CVE-2012-3492 allow?
CVE-2012-3492 allows remote attackers to impersonate users by leveraging weak permissions on authentication directories.
Where can I find more information about CVE-2012-3492?
More information about CVE-2012-3492 can typically be found in the release notes for Condor software.