CVE-2017-16816: Input Validation
Published Jul 5, 2018
·Updated
The condorschedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
Affected Software
2 affected components
Wisc Htcondor<8.6.8
Wisc Htcondor>=8.7.0<8.7.5
Event History
Jul 5, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16816?
The severity of CVE-2017-16816 is rated as medium with a score of 6.5.
2
How do I fix CVE-2017-16816?
To fix CVE-2017-16816, upgrade HTCondor to version 8.6.8 or 8.7.5 or later.
3
What component is affected by CVE-2017-16816?
The condor_schedd component in HTCondor is affected by CVE-2017-16816.
4
What type of attack does CVE-2017-16816 facilitate?
CVE-2017-16816 allows remote authenticated users to perform a denial of service attack leading to a daemon crash.
5
Which versions of HTCondor are vulnerable to CVE-2017-16816?
HTCondor versions before 8.6.8 and 8.7.0 to 8.7.5 are vulnerable to CVE-2017-16816.