CVE-2013-4495

Description

From CVE.org

The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Acknowledgements

Red Hat would like to thank David Beer (Adaptive Computer) for reporting this issue. Upstream acknowledges Matt Ezell (Oak Ridge National Labs) as the original reporter.

Frequently Asked Questions

Want to get errata notifications? Sign up here.