Vulnerabilities
Vulnerable Software
Globus:  >> Globus Toolkit  >> 5.0.1  Security Vulnerabilities
The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.
CVSS Score
7.6
EPSS Score
0.025
Published
2012-06-07
MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.
CVSS Score
4.3
EPSS Score
0.008
Published
2011-02-02


Contact Us

Shodan ® - All rights reserved