[SECURITY] Fedora 20 Update: torque-3.0.4-6.fc20

updates at fedoraproject.org updates at fedoraproject.org
Sat Oct 18 16:59:37 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-11989
2014-10-03 02:59:33
--------------------------------------------------------------------------------

Name        : torque
Product     : Fedora 20
Version     : 3.0.4
Release     : 6.fc20
URL         : http://www.adaptivecomputing.com/products/open-source/torque/
Summary     : Tera-scale Open-source Resource and QUEue manager
Description :
TORQUE (Tera-scale Open-source Resource and QUEue manager) is a resource
manager providing control over batch jobs and distributed compute nodes.
TORQUE is based on OpenPBS version 2.3.12 and incorporates scalability,
fault tolerance, and feature extension patches provided by USC, NCSA, OSC,
the U.S. Dept of Energy, Sandia, PNNL, U of Buffalo, TeraGrid, and many
other leading edge HPC organizations.

This package holds just a few shared files and directories.

--------------------------------------------------------------------------------
Update Information:

Fix CVE-2013-4319 (RHBZ #1005918, #1005919)

    Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
Fix CVE-2013-4495: arbitrary code execution via job submission (RHBZ #1029752)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Oct  1 2014 Haïkel Guémar <hguemar at fedoraproject.org> - 3.0.4-6
- Fix CVE-2013-4319 (RHBZ #1005918, #1005919)
* Fri Sep  5 2014 Haïkel Guémar <hguemar at fedoraproject.org> - 3.0.4-5
- Fix CVE-2013-4495 (RHBZ #1029752)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1005918 - CVE-2013-4319 torque: remote arbitrary command execution as root on cluster
        https://bugzilla.redhat.com/show_bug.cgi?id=1005918
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update torque' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list