[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251782

 
 

909

 
 

196543

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4023-1 slurm-llnl -- slurm-llnl

ID: oval:org.secpod.oval:def:603159Date: (C)2021-01-06   (M)2023-04-19
Class: PATCHFamily: unix




Ryan Day discovered that the Simple Linux Utility for Resource Management , a cluster resource management and job scheduling system, does not properly handle SPANK environment variables, allowing a user permitted to submit jobs to execute code as root during the Prolog or Epilog. All systems using a Prolog or Epilog script are vulnerable, regardless of whether SPANK plugins are in use.

Platform:
Debian 9.x
Product:
libslurmdb30
slurmctld
libpmi2-0
libslurmdb-perl
slurm-llnl
slurmd
libpmi0
slurm-wlm
libslurm-dev
libslurm30
slurm-client
libslurmdb-dev
sview
libslurm-perl
libpam-slurm
Reference:
DSA-4023-1
CVE-2017-15566
CVE    1
CVE-2017-15566
CPE    2
cpe:/a:schedmd:libslurm-dev
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies