Vulnerability Description
The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wisc | Htcondor | < 8.6.8 |
Related Weaknesses (CWE)
References
- http://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2017-0001MitigationVendor Advisory
- https://www-auth.cs.wisc.edu/lists/htcondor-users/2017-November/msg00022.shtmlMailing ListVendor Advisory
- http://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2017-0001MitigationVendor Advisory
- https://www-auth.cs.wisc.edu/lists/htcondor-users/2017-November/msg00022.shtmlMailing ListVendor Advisory
FAQ
What is CVE-2017-16816?
CVE-2017-16816 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions.
How severe is CVE-2017-16816?
CVE-2017-16816 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16816?
Check the references section above for vendor advisories and patch information. Affected products include: Wisc Htcondor.