USN-4771-1: HTCondor vulnerabilities
15 March 2021
Several security issues were fixed in HTCondor.
Releases
Packages
- condor - distributed workload management system
Details
It was discovered that HTCondor incorrectly invoked the mailx utility. An
attacker could use this vulnerability to execute arbitrary commands. This
issue only affected Ubuntu 14.04 ESM. (CVE-2014-8126)
It was discovered that HTCondor mishandled certain crafted input. An
attacker could use this vulnerability to cause HTCondor to crash.
(CVE-2017-16816)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libclassad7
-
8.4.2~dfsg.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
condor
-
8.4.2~dfsg.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
htcondor
-
8.4.2~dfsg.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
htcondor
-
8.0.5~dfsg.1-1ubuntu1+esm1
Available with Ubuntu Pro
-
libclassad5
-
8.0.5~dfsg.1-1ubuntu1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.