Bug 1169800 (CVE-2014-8126)

Summary: CVE-2014-8126 condor: mailx invocation enables code execution as condor user
Product: [Other] Security Response Reporter: Florian Weimer <fweimer>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: bhu, chazlett, esammons, iboverma, jross, jrusnack, ltoscano, matt, mcressma, security-response-team, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: condor 8.2.6 Doc Type: Bug Fix
Doc Text:
The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-01-12 20:54:38 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1171136, 1181291    
Bug Blocks: 1174797    
Attachments:
Description Flags
sendmail.patch none

Description Florian Weimer 2014-12-02 13:26:03 UTC
The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user.

Acknowledgements:

This issue was discovered by Florian Weimer of Red Hat Product Security.

Comment 9 Florian Weimer 2015-01-08 16:32:27 UTC
Created attachment 977841 [details]
sendmail.patch

This patch also needs a configuration file change to set the SENDMAIL parameter.

Comment 10 Vincent Danen 2015-01-12 19:59:42 UTC
Created condor tracking bugs for this issue:

Affects: fedora-all [bug 1181291]

Comment 11 errata-xmlrpc 2015-01-12 20:15:11 UTC
This issue has been addressed in the following products:

  MRG for RHEL-5 v. 2

Via RHSA-2015:0036 https://rhn.redhat.com/errata/RHSA-2015-0036.html

Comment 12 errata-xmlrpc 2015-01-12 20:25:40 UTC
This issue has been addressed in the following products:

  MRG for RHEL-6 v.2

Via RHSA-2015:0035 https://rhn.redhat.com/errata/RHSA-2015-0035.html

Comment 13 Fedora Update System 2015-07-18 01:55:43 UTC
condor-8.3.6-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.