Candidate: CVE-2012-5390 PublicDate: 2014-06-06 14:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5390 http://research.cs.wisc.edu/htcondor/security/vulnerabilities/CONDOR-2012-0003.html Description: The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697936 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_condor: upstream_condor: released (7.8.6~dfsg.1-1) hardy_condor: DNE lucid_condor: ignored (reached end-of-life) oneiric_condor: ignored (reached end-of-life) precise_condor: DNE quantal_condor: ignored (reached end-of-life) raring_condor: ignored (reached end-of-life) saucy_condor: not-affected (7.8.8~dfsg.1-2) trusty_condor: not-affected (8.0.5~dfsg.1-1ubuntu1) trusty/esm_condor: DNE (trusty was not-affected [8.0.5~dfsg.1-1ubuntu1]) devel_condor: not-affected (8.0.5~dfsg.1-1ubuntu1)