• [SECURITY] [DSA 2770-1] torque security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed Oct 9 16:40:02 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2770-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso October 09, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : torque
    Vulnerability : authentication bypass
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2013-4319
    Debian Bug : 722306

    John Fitzpatrick of MWR InfoSecurity discovered an authentication bypass vulnerability in torque, a PBS-derived batch processing queueing system.

    The torque authentication model revolves around the use of privileged
    ports. If a request is not made from a privileged port then it is
    assumed not to be trusted or authenticated. It was found that pbs_mom
    does not perform a check to ensure that connections are established
    from a privileged port.

    A user who can run jobs or login to a node running pbs_server or pbs_mom
    can exploit this vulnerability to remotely execute code as root on the
    cluster by submitting a command directly to a pbs_mom daemon
    to queue and run a job.

    For the oldstable distribution (squeeze), this problem has been fixed in version 2.4.8+dfsg-9squeeze2.

    For the stable distribution (wheezy), this problem has been fixed in
    version 2.4.16+dfsg-1+deb7u1.

    For the unstable distribution (sid), this problem will be fixed soon.

    We recommend that you upgrade your torque packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.14 (GNU/Linux)

    iQIcBAEBCgAGBQJSVWfFAAoJEAVMuPMTQ89E6Z8P/20uNyrICGD4ut8gjo9SN91S rCH5IfPwaIqS9cwZBkoqlRKxSc54d5eO7dlSGeOEpuB5KExYHi/h9KmS/Ja31pUO nCZ9onijhiyIr7d1+7YIVQpBXA7E3QxDXC5462ZtCuM9OPwFO22yspQKq9TfI2U+ hAhuRPnb6J7+7i8WQubpOLGynhuy4EJaYBTNiL7i9Z/Na7iWKRTHioFb92y4Y/pT sFpQ1r5EMVDzmJ8UzmyrWbdWMumKKoiGzgBCan9UKtkX2l4i8wjmc3ypifox+1zo lJqoBXh0PFrRtyHYwFAAU2oujuNdxgTwBD9al7Jip/0FHtEbhGum1VwIx9t95JrZ PsrjWjXZWdydRQHflBoGj3pKxD0UPH+OcEWgXpR8gGsID0g17muKRIuztAwFtrbR yLOpV0sobzR5GWaBFfwbIf+zziljqNKhXe1DgAjjegUuWD9Y4HP0H2pb42bp5ybx L9avUTjn9GOz428cAuj2PBLPaBLrtlvXePgjk88sl+Gf6Dt1SWqtH5niFgQtwhfV XFwIG6zBhCJp6jW2CyZxXHMkWgOWTAIOTb7B4R77y8MTyAnK/Ua30x4DFAaF4qli ARF6BsI3h6VjU835sDPJlaPHu+0KwM5Q7xOswuNtxyNYsuxVD2+ap+e0zIYlEod0 aO3eNNSfeTDJq1B2aD54
    =0S9S
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)