~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2014-3684

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2014-3684
2
 
PublicDate: 2014-10-30
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3684
5
 
 https://github.com/adaptivecomputing/torque/commit/967cdc80150690459a47a35a658abeee0ca6e5cb
6
 
 https://github.com/adaptivecomputing/torque/commit/f2f4c950f3d461a249111c8826da3beaafccace9
7
 
Description:
8
 
 The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource
9
 
 and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and
10
 
 earlier does not validate that the owner of the process also owns the
11
 
 adopted session id, which allows remote authenticated users to kill
12
 
 arbitrary processes via a crafted executable.
13
 
Ubuntu-Description:
14
 
Notes:
15
 
Bugs:
16
 
Priority: medium
17
 
Discovered-by:
18
 
Assigned-to:
19
 
 
20
 
Patches_torque:
21
 
upstream_torque: needs-triage
22
 
lucid_torque: ignored (reached end-of-life)
23
 
precise_torque: released (2.4.16+dfsg-1+deb7u4build0.12.04.1)
24
 
precise/esm_torque: DNE (precise was released [2.4.16+dfsg-1+deb7u4build0.12.04.1])
25
 
trusty_torque: needs-triage
26
 
utopic_torque: ignored (reached end-of-life)
27
 
vivid_torque: not-affected (2.4.16+dfsg-1.5)
28
 
vivid/stable-phone-overlay_torque: DNE
29
 
vivid/ubuntu-core_torque: DNE
30
 
wily_torque: not-affected (2.4.16+dfsg-1.5)
31
 
xenial_torque: not-affected (2.4.16+dfsg-1.5)
32
 
yakkety_torque: not-affected (2.4.16+dfsg-1.5)
33
 
zesty_torque: DNE
34
 
artful_torque: DNE
35
 
bionic_torque: DNE
36
 
devel_torque: DNE