Vulnerabilities
Vulnerable Software
Platform:  Security Vulnerabilities
Buffer overflow in eauth in Load Sharing Facility 4.x, 5.x, and 6.x allows local users or remote attackers within the LSF cluster to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long LSF_From_PC parameter.
CVSS Score
10.0
EPSS Score
0.028
Published
2004-11-23
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.
CVSS Score
10.0
EPSS Score
0.035
Published
2004-11-23
The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.
CVSS Score
4.6
EPSS Score
0.001
Published
2003-05-22


Contact Us

Shodan ® - All rights reserved