The sendthemail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtorque2",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "libtorque2-dev",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-client",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-client-x11",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-common",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-mom",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-pam",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-scheduler",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
},
{
"binary_name": "torque-server",
"binary_version": "2.4.16+dfsg-1.3ubuntu1"
}
]
}