The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and...
Vulnerability Description
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted executable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-3684
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159259.html
- http://openwall.com/lists/oss-security/2014/10/02/45
- http://advisories.mageia.org/MGASA-2014-0408.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159201.html
- http://secunia.com/advisories/61960
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159183.html
- http://www.debian.org/security/2014/dsa-3058
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:124
- http://openwall.com/lists/oss-security/2014/10/02/44
- http://secunia.com/advisories/61350
More from adaptivecomputing
View All →Affected Vendor
adaptivecomputing
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.