Bug 1169800 (CVE-2014-8126) - CVE-2014-8126 condor: mailx invocation enables code execution as condor user
Summary: CVE-2014-8126 condor: mailx invocation enables code execution as condor user
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-8126
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1171136 1181291
Blocks: 1174797
TreeView+ depends on / blocked
 
Reported: 2014-12-02 13:26 UTC by Florian Weimer
Modified: 2023-05-12 06:26 UTC (History)
11 users (show)

Fixed In Version: condor 8.2.6
Doc Type: Bug Fix
Doc Text:
The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user.
Clone Of:
Environment:
Last Closed: 2015-01-12 20:54:38 UTC
Embargoed:


Attachments (Terms of Use)
sendmail.patch (5.55 KB, patch)
2015-01-08 16:32 UTC, Florian Weimer
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0035 0 normal SHIPPED_LIVE Important: condor security update 2015-01-13 01:25:27 UTC
Red Hat Product Errata RHSA-2015:0036 0 normal SHIPPED_LIVE Important: condor security update 2015-01-13 01:14:51 UTC

Description Florian Weimer 2014-12-02 13:26:03 UTC
The HTCondor scheduler can optionally notify a user of completed jobs by sending an email. Due to the way the daemon sent the email message, authenticated users able to submit jobs could execute arbitrary code with the privileges of the condor user.

Acknowledgements:

This issue was discovered by Florian Weimer of Red Hat Product Security.

Comment 9 Florian Weimer 2015-01-08 16:32:27 UTC
Created attachment 977841 [details]
sendmail.patch

This patch also needs a configuration file change to set the SENDMAIL parameter.

Comment 10 Vincent Danen 2015-01-12 19:59:42 UTC
Created condor tracking bugs for this issue:

Affects: fedora-all [bug 1181291]

Comment 11 errata-xmlrpc 2015-01-12 20:15:11 UTC
This issue has been addressed in the following products:

  MRG for RHEL-5 v. 2

Via RHSA-2015:0036 https://rhn.redhat.com/errata/RHSA-2015-0036.html

Comment 12 errata-xmlrpc 2015-01-12 20:25:40 UTC
This issue has been addressed in the following products:

  MRG for RHEL-6 v.2

Via RHSA-2015:0035 https://rhn.redhat.com/errata/RHSA-2015-0035.html

Comment 13 Fedora Update System 2015-07-18 01:55:43 UTC
condor-8.3.6-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.