Vulnerability Description
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remote authenticated users to kill arbitrary processes via a crafted executable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adaptivecomputing | Torque Resource Manager | 4.2.3 |
Related Weaknesses (CWE)
References
- http://advisories.mageia.org/MGASA-2014-0408.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159183.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159201.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159259.html
- http://openwall.com/lists/oss-security/2014/10/02/44
- http://openwall.com/lists/oss-security/2014/10/02/45
- http://secunia.com/advisories/61350
- http://secunia.com/advisories/61960
- http://www.debian.org/security/2014/dsa-3058
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:124
- http://advisories.mageia.org/MGASA-2014-0408.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159183.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159201.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159259.html
- http://openwall.com/lists/oss-security/2014/10/02/44
FAQ
What is CVE-2014-3684?
CVE-2014-3684 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the proc...
How severe is CVE-2014-3684?
CVE-2014-3684 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3684?
Check the references section above for vendor advisories and patch information. Affected products include: Adaptivecomputing Torque Resource Manager.