Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20110811015232.GH1360@redhat.com>
Date: Wed, 10 Aug 2011 19:52:32 -0600
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2011-2907: authentication bypass in torque

Just a heads up on a security flaw in torque that can makes it
vulnerable to an authorization bypass.

The gory details are available here:

http://www.clusterresources.com/pipermail/torqueusers/2011-August/013194.html
https://bugzilla.redhat.com/show_bug.cgi?id=713090

The long and short of it is that if you ship torque compiled with munge
support, you are not vulnerable.

This issue was assigned the name CVE-2011-2907.

-- 
Vincent Danen / Red Hat Security Response Team 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.