VDB
GCVE-VVD-MAGEIA-2014-408
GCVE-VVD-MAGEIA-2014-408
Advisory Published
Updated torque packages fix security vulnerabilities:
Chad Vizino reported that within a TORQUE Resource Manager job a non-root
user could use a vulnerability in the tm_adopt() library call to kill
processes
he/she doesn't own including root-owned ones on any node in a job
(CVE-2014-3684).
This update implements the upstream fixes.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | torque | 0 (affected), 4.1.6-4.1.mga4 (unaffected) | — |
| Mageia | torque | 0 (affected), 4.1.5.1-1.3.mga3 (unaffected) | — |
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.