Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to gain privileges via vectors involving a long host variable in pbs_iff.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Clusterresources TORQUE Resource Manager Job和Host名称处理缓冲区溢出漏洞
Vulnerability Description
TORQUE Resource Manager 2.4.14之前版本中存在两个缓冲区溢出漏洞。远程攻击者可利用这些漏洞获得特权。 (1)当处理Job名称时,src/server/req_quejob.c中存在边界错误,攻击者可借助作为Job名称传递的超长字符串导致缓冲区溢出。 (2)当处理Host名称时,src/lib/Libnet/get_hostaddr.c中存在边界错误,攻击者可借助作为Host名称传递的超长字符串导致缓冲区溢出。
CVSS Information
N/A
Vulnerability Type
N/A