Summary
The remote host is missing an update to slurm-llnl announced via advisory DSA 1776-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201776-1
Insight
It was discovered that the Simple Linux Utility for Resource Management (SLURM), a cluster job management and scheduling system, did not drop the supplemental groups. These groups may be system groups with elevated privileges, which may allow a valid SLURM user to gain elevated privileges.
The old stable distribution (etch) does not contain a slurm-llnl package.
For the stable distribution (lenny), this problem has been fixed in version 1.3.6-1lenny3.
For the unstable distribution (sid), this problem has been fixed in version 1.3.15-1.
We recommend that you upgrade your slurm-llnl package.
Severity
Classification
-
CVE CVE-2009-2084 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities