You are here
Home > Preporuke > Ranjivost programskog paketa torque

Ranjivost programskog paketa torque

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-11989
2014-10-03 02:59:33
——————————————————————————–

Name : torque
Product : Fedora 20
Version : 3.0.4
Release : 6.fc20
URL : http://www.adaptivecomputing.com/products/open-source/torque/
Summary : Tera-scale Open-source Resource and QUEue manager
Description :
TORQUE (Tera-scale Open-source Resource and QUEue manager) is a resource
manager providing control over batch jobs and distributed compute nodes.
TORQUE is based on OpenPBS version 2.3.12 and incorporates scalability,
fault tolerance, and feature extension patches provided by USC, NCSA, OSC,
the U.S. Dept of Energy, Sandia, PNNL, U of Buffalo, TeraGrid, and many
other leading edge HPC organizations.

This package holds just a few shared files and directories.

——————————————————————————–
Update Information:

Fix CVE-2013-4319 (RHBZ #1005918, #1005919)

Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
——————————————————————————–
ChangeLog:

* Wed Oct 1 2014 Haïkel Guémar <hguemar@fedoraproject.org> – 3.0.4-6
– Fix CVE-2013-4319 (RHBZ #1005918, #1005919)
* Fri Sep 5 2014 Haïkel Guémar <hguemar@fedoraproject.org> – 3.0.4-5
– Fix CVE-2013-4495 (RHBZ #1029752)
——————————————————————————–
References:

[ 1 ] Bug #1005918 – CVE-2013-4319 torque: remote arbitrary command execution as root on cluster
https://bugzilla.redhat.com/show_bug.cgi?id=1005918
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update torque’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-12059
2014-10-03 03:02:22
——————————————————————————–

Name : torque
Product : Fedora 19
Version : 3.0.4
Release : 5.fc19
URL : http://www.adaptivecomputing.com/products/open-source/torque/
Summary : Tera-scale Open-source Resource and QUEue manager
Description :
TORQUE (Tera-scale Open-source Resource and QUEue manager) is a resource
manager providing control over batch jobs and distributed compute nodes.
TORQUE is based on OpenPBS version 2.3.12 and incorporates scalability,
fault tolerance, and feature extension patches provided by USC, NCSA, OSC,
the U.S. Dept of Energy, Sandia, PNNL, U of Buffalo, TeraGrid, and many
other leading edge HPC organizations.

This package holds just a few shared files and directories.

——————————————————————————–
Update Information:

Fix CVE-2013-4319 (RHBZ #1005918, #1005919)

Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
——————————————————————————–
ChangeLog:

* Wed Oct 1 2014 Haïkel Guémar <hguemar@fedoraproject.org> – 3.0.4-5
– Fix CVE-2013-4319 (RHBZ #1005918, #1005919)
* Fri Sep 5 2014 Haïkel Guémar <hguemar@fedoraproject.org> – 3.0.4-4
– Fix CVE-2013-4495 (RHBZ #1029752)
– Add missing BRs for latex docs
* Fri Feb 15 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 3.0.4-3
– Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
* Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> – 3.0.4-2
– Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
——————————————————————————–
References:

[ 1 ] Bug #1005918 – CVE-2013-4319 torque: remote arbitrary command execution as root on cluster
https://bugzilla.redhat.com/show_bug.cgi?id=1005918
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update torque’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2014-10-0022-ADV
CveCVE-2013-4319 CVE-2013-4495
ID izvornikaFEDORA-2014-11989 FEDORA-2014-12059
Proizvodtorque
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa glibc

Otkriveni su sigurnosni nedostaci u programskom paketu glibc za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog...

Close