6.9
CVSSv2

CVE-2010-3380

Published: 29/09/2010 Updated: 30/09/2010
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The (1) init.d/slurm and (2) init.d/slurmdbd scripts in SLURM prior to 2.1.14 place the . (dot) directory in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Vulnerable Product Search on Vulmon Subscribe to Product

llnl slurm 2.1.1

llnl slurm 2.1.0

llnl slurm 2.0.9

llnl slurm 2.0.8

llnl slurm 2.0.7

llnl slurm 1.3.10

llnl slurm

llnl slurm 2.1.5

llnl slurm 2.1.2

llnl slurm 2.0.5

llnl slurm 2.0.3

llnl slurm 1.3.14

llnl slurm 1.3.12

llnl slurm 2.1.10

llnl slurm 2.1.9

llnl slurm 2.1.8

llnl slurm 2.1.7

llnl slurm 2.0.2

llnl slurm 2.0.1

llnl slurm 2.0.0

llnl slurm 1.3.15

llnl slurm 2.1.12

llnl slurm 2.1.11

llnl slurm 2.1.6

llnl slurm 2.1.4

llnl slurm 2.0.6

llnl slurm 2.0.4

llnl slurm 1.3.13

llnl slurm 1.3.11

Vendor Advisories

Debian Bug report logs - #602340 CVE-2010-3380 Package: slurm-llnl; Maintainer for slurm-llnl is Debian HPC Team <debian-hpc@listsdebianorg>; Source for slurm-llnl is src:slurm-llnl (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 3 Nov 2010 21:57:02 UTC Severity: grave Tags: secu ...