CVE-2014-0748

apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:cray:cray_linux_environment:*:*:*:*:*:*:*:*
cpe:2.3:o:cray:cray_linux_environment:5.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-12-27 02:59

Updated : 2024-02-28 12:20


NVD link : CVE-2014-0748

Mitre link : CVE-2014-0748

CVE.ORG link : CVE-2014-0748


JSON object : View

Products Affected

cray

  • cray_linux_environment
CWE
CWE-20

Improper Input Validation