CVE Database


Impact: Low
Public: 2012-09-28
Bugzilla: 860850: CVE-2012-4462 condor: DoS when removing jobs via when job id is in square brackets


The MITRE CVE dictionary describes this issue as:

aviary/ in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.

Find out more about CVE-2012-4462 from the MITRE CVE dictionary and NIST NVD.


The Red Hat Security Response Team has rated this issue as having low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification:

CVSS v2 metrics

Base Score: 3.5
Base Metrics: AV:N/AC:M/Au:S/C:N/I:N/A:P
Access Vector: Network
Access Complexity: Medium
Authentication: Single Instance
Confidentiality Impact: None
Integrity Impact: None
Availability Impact: Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat security errata

Platform Errata Release Date
MRG Grid for RHEL 5 Server v.2 RHSA-2013:0564 March 06, 2013
MRG Grid for RHEL 6 Server v.2 RHSA-2013:0565 March 06, 2013

External References


This issue was discovered by Daniel Horak of the Red Hat Enterprise MRG Quality Engineering Team.

This page is generated automatically and has not been checked for errors or omissions.

For clarification or corrections please contact the Red Hat Security Response Team.