Login
Newsletter
Werbung

Sicherheit: Denial of Service in torque
Aktuelle Meldungen Distributionen
Name: Denial of Service in torque
ID: FEDORA-2015-8577
Distribution: Fedora
Plattformen: Fedora 20
Datum: Sa, 30. Mai 2015, 18:38
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3684
Applikationen: TORQUE Resource Manager

Originalnachricht

Name        : torque
Product : Fedora 20
Version : 4.2.10
Release : 3.fc20
URL : http://www.adaptivecomputing.com/products/open-source/torque/
Summary : Tera-scale Open-source Resource and QUEue manager
Description :
TORQUE (Tera-scale Open-source Resource and QUEue manager) is a resource
manager providing control over batch jobs and distributed compute nodes.
TORQUE is based on OpenPBS version 2.3.12 and incorporates scalability,
fault tolerance, and feature extension patches provided by USC, NCSA, OSC,
the U.S. Dept of Energy, Sandia, PNNL, U of Buffalo, TeraGrid, and many
other leading edge HPC organizations.

This package holds just a few shared files and directories.

-------------------------------------------------------------------------------
-
Update Information:

Bugfix - #1215207 create/install service files for these
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue May 19 2015 David Brown <david.brown@pnnl.gov> - 4.2.10-3
- Bugfix - #1215207 create/install service files for these
- Bugfix - #1117263 qmgr aborts in some instances
- Bugfix - #1144396 Hey! Version Bump!
- Bugfix - #1215992 more service scripts
- Bugfix - #1216037 fixed permissions on directories
- Bugfix - #1149045 hopefully these are all fixed now
- Bugfix - #965513 calling this one fixed...
* Fri Apr 24 2015 David Brown <david.brown@pnnl.gov> - 4.2.10-2
- Bugfix - #1154413 make manipulating services better.
* Mon Apr 6 2015 David Brown <david.brown@pnnl.gov> - 4.2.10-1
- Updated upstream version
* Thu Apr 2 2015 David Brown <david.brown@pnnl.gov> - 4.2.8-3
- Version bump to merge from previous version
* Thu Mar 26 2015 Richard Hughes <rhughes@redhat.com> - 4.2.8-2
- Add an AppData file for the software center
* Tue Oct 14 2014 David Brown <david.brown@pnnl.gov> - 4.2.8-2
- merged fedora latest into epel
- This breaks old configs and should be treated carefully
* Wed Oct 1 2014 Haïkel Guémar <hguemar@fedoraproject.org> - 3.0.4-6
- Fix CVE-2013-4319 (RHBZ #1005918, #1005919)
* Fri Sep 5 2014 Haïkel Guémar <hguemar@fedoraproject.org> - 3.0.4-5
- Fix CVE-2013-4495 (RHBZ #1029752)
* Mon Sep 1 2014 Haïkel Guémar <hguemar@fedoraproject.org> - 4.2.8-1
- upstream 4.2.8
* Mon Aug 18 2014 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 4.2.6.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Thu Jul 17 2014 Ralf Corsépius <corsepiu@fedoraproject.org> - 4.2.6.1-5
- Reflect upstream URL and Source0 having changed.
* Thu Jul 17 2014 Ralf Corsépius <corsepiu@fedoraproject.org> - 4.2.6.1-4
- Append -DUSE_INTERP_RESULT -DUSE_INTERP_ERRORLINE to CFLAGS to work-around
Tcl/Tk-8.6 incompatibilities (FTFFS RHBZ#1107455).
- Pass --without-debug to %configure to let configure pass through
%optflags (RHBZ#1074571).
- Fix twice listed files in *-devel.
* Sun Jun 8 2014 Fedora Release Engineering
<rel-eng@lists.fedoraproject.org> - 4.2.6.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Wed May 21 2014 Jaroslav Škarvada <jskarvad@redhat.com> - 4.2.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Changes/f21tcl86
* Sun Jan 12 2014 Haïkel Guémar <hguemar@fedoraproject.org> - 4.2.6.1-1
- upstream 4.2.6.1
* Wed Nov 13 2013 Haïkel Guémar <hguemar@fedoraproject.org> - 4.2.6-1
- upstream 4.2.6
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1215207 - pbs_server does not start trqauthd
https://bugzilla.redhat.com/show_bug.cgi?id=1215207
[ 2 ] Bug #1117263 - torque qmgr aborts on server commands while jobs are
running
https://bugzilla.redhat.com/show_bug.cgi?id=1117263
[ 3 ] Bug #1144396 - torque-4.2.10 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1144396
[ 4 ] Bug #1215992 - torque-client (4.x) should package trqauthd service
https://bugzilla.redhat.com/show_bug.cgi?id=1215992
[ 5 ] Bug #1216037 - permissions on some /var/lib/torque/ sub-directories
https://bugzilla.redhat.com/show_bug.cgi?id=1216037
[ 6 ] Bug #1149045 - CVE-2014-3684 torque: non-root users able to kill any
process on any node in a job [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1149045
[ 7 ] Bug #965513 - torque package should be built with PIE flags
https://bugzilla.redhat.com/show_bug.cgi?id=965513
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update torque' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung