First published: Mon Dec 21 2009(Updated: )
Condor is a specialized workload management system for compute-intensive<br>jobs. It provides a job queuing mechanism, scheduling policy, priority<br>scheme, and resource monitoring and management.<br>A flaw was found in the way Condor managed jobs. This could allow a user<br>that is authorized to submit jobs into Condor to queue a job as if it were<br>submitted by a different local user, potentially leading to unauthorized<br>access to that user's account. (CVE-2009-4133)<br>Note: Condor will not run jobs as root; therefore, this flaw cannot lead to<br>a compromise of the root user account.<br>All Red Hat Enterprise MRG 1.2 users are advised to upgrade to these<br>updated packages, which contain a backported patch to correct this issue.<br>Condor must be restarted for the update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat MRG Realtime |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:1689 is classified as moderate.
To fix RHSA-2009:1689, you should apply the latest updates provided by Red Hat that address this vulnerability.
RHSA-2009:1689 affects systems running the Condor workload management system.
The flaw in RHSA-2009:1689 involves the way Condor manages jobs, which can lead to potential user exploitation.
There is no official workaround for RHSA-2009:1689, so updating to a fixed version is recommended.