Bug 772058 (CVE-2011-4925) - CVE-2011-4925 torque: munge authentication security bypass flaw
Summary: CVE-2011-4925 torque: munge authentication security bypass flaw
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2011-4925
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 772059
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-01-05 20:39 UTC by Vincent Danen
Modified: 2019-09-29 12:49 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-01-12 02:31:07 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2012-01-05 20:39:28 UTC
A vulnerability was reported [1],[2] in TORQUE that could be exploited by a malicious user to bypass certain security restrictions.  This is due to an unspecified error when using munge authentication, which a malicious user could exploit to impersonate another user.

Upstream has released 2.5.9 to correct this flaw.  It is unclear whether or not 3.x is affected; 3.0.3 was released 10 days after 2.5.9 but no mention of this flaw exists in the changelog, so it may not be affected (or it may be affected and not fixed, it is difficult to say).  I have not been able to find a patch which could be used to check.

[1] http://www.adaptivecomputing.com/resources/docs/torque/3-0-3/changelog.php#259
[2] http://secunia.com/advisories/47381

Comment 1 Vincent Danen 2012-01-05 20:40:32 UTC
Created torque tracking bugs for this issue

Affects: epel-all [bug 772059]

Comment 2 Vincent Danen 2012-01-05 20:45:37 UTC
I've not filed a tracking bug for Fedora because I'm not sure whether or not it's affected, and whether or not even updating to 3.0.3 will fix anything.

Comment 3 Steve Traylen 2012-01-11 16:19:57 UTC
This is duplicate of:


https://bugzilla.redhat.com/show_bug.cgi?id=752079

and is released for for .el4, 5 and 6 and Fedora 16.

Comment 4 Vincent Danen 2012-01-12 02:31:07 UTC
Indeed.  Thank you, this has been addressed for all branches (including Fedora 15, which has just been submitted as an update).


Note You need to log in before you can comment on or make changes to this bug.