RHSA-2009:1689: Moderate: condor security update
Condor is a specialized workload management system for compute-intensivejobs. It provides a job queuing mechanism, scheduling policy, priorityscheme, and resource monitoring and management.A flaw was found in the way Condor managed jobs. This could allow a userthat is authorized to submit jobs into Condor to queue a job as if it weresubmitted by a different local user, potentially leading to unauthorizedaccess to that user's account. (CVE-2009-4133)Note: Condor will not run jobs as root; therefore, this flaw cannot lead toa compromise of the root user account.All Red Hat Enterprise MRG 1.2 users are advised to upgrade to theseupdated packages, which contain a backported patch to correct this issue.Condor must be restarted for the update to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1689?
The severity of RHSA-2009:1689 is classified as moderate.
How do I fix RHSA-2009:1689?
To fix RHSA-2009:1689, you should apply the latest updates provided by Red Hat that address this vulnerability.
What systems are affected by RHSA-2009:1689?
RHSA-2009:1689 affects systems running the Condor workload management system.
What is the nature of the flaw in RHSA-2009:1689?
The flaw in RHSA-2009:1689 involves the way Condor manages jobs, which can lead to potential user exploitation.
Is there a workaround for RHSA-2009:1689?
There is no official workaround for RHSA-2009:1689, so updating to a fixed version is recommended.