Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBSOHOST variable to the qsub program.
{
"binaries": [
{
"binary_name": "libtorque2",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-client",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-client-x11",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-common",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-mom",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-pam",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-scheduler",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
},
{
"binary_name": "torque-server",
"binary_version": "2.4.16+dfsg-1.3ubuntu1.1"
}
]
}
{
"binaries": [
{
"binary_name": "libtorque2",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-client",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-client-x11",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-common",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-mom",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-pam",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-scheduler",
"binary_version": "2.4.16+dfsg-1.5"
},
{
"binary_name": "torque-server",
"binary_version": "2.4.16+dfsg-1.5"
}
]
}