CVE-2012-3416

Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:condor_project:condor:*:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.5.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.5:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.6:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.7:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.8:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:6.8.9:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.00:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.01:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.02:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.2.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.03:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.3.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.8.0:*:*:*:*:*:*:*

History

13 Feb 2023, 04:34

Type Values Removed Values Added
Summary CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname.
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2012:1168', 'name': 'https://access.redhat.com/errata/RHSA-2012:1168', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=841175', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=841175', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2012:1169', 'name': 'https://access.redhat.com/errata/RHSA-2012:1169', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2012-3416', 'name': 'https://access.redhat.com/security/cve/CVE-2012-3416', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:15

Type Values Removed Values Added
Summary Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a spoofed reverse DNS hostname. CVE-2012-3416 condor: host based authentication does not implement forward-confirmed reverse dns
References
  • (MISC) https://access.redhat.com/errata/RHSA-2012:1168 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=841175 -
  • (MISC) https://access.redhat.com/errata/RHSA-2012:1169 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2012-3416 -

Information

Published : 2012-08-25 10:29

Updated : 2023-12-10 11:16


NVD link : CVE-2012-3416

Mitre link : CVE-2012-3416

CVE.ORG link : CVE-2012-3416


JSON object : View

Products Affected

condor_project

  • condor
CWE
CWE-287

Improper Authentication