The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "htcondor",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
},
{
"binary_name": "htcondor-dbg",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
},
{
"binary_name": "htcondor-dev",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
},
{
"binary_name": "htcondor-doc",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
},
{
"binary_name": "libclassad-dev",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
},
{
"binary_name": "libclassad5",
"binary_version": "8.0.5~dfsg.1-1ubuntu1"
}
]
}