[SECURITY] Fedora EPEL 5 Update: torque-4.2.10-1.el5

updates at fedoraproject.org updates at fedoraproject.org
Thu Apr 23 19:03:16 UTC 2015


--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2015-5724
2015-04-08 17:32:17
--------------------------------------------------------------------------------

Name        : torque
Product     : Fedora EPEL 5
Version     : 4.2.10
Release     : 1.el5
URL         : http://www.adaptivecomputing.com/products/open-source/torque/
Summary     : Tera-scale Open-source Resource and QUEue manager
Description :
TORQUE (Tera-scale Open-source Resource and QUEue manager) is a resource
manager providing control over batch jobs and distributed compute nodes.
TORQUE is based on OpenPBS version 2.3.12 and incorporates scalability,
fault tolerance, and feature extension patches provided by USC, NCSA, OSC,
the U.S. Dept of Energy, Sandia, PNNL, U of Buffalo, TeraGrid, and many
other leading edge HPC organizations.

This package holds just a few shared files and directories.

--------------------------------------------------------------------------------
Update Information:

Updated upstream version
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1005920 - CVE-2013-4319 torque: remote arbitrary command execution as root on cluster [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1005920
  [ 2 ] Bug #1098583 - CVE-2014-0749 torque: buffer overflow exists in versions of TORQUE which can be exploited in order to remotely execute code from an unauthenticated perspective [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1098583
  [ 3 ] Bug #1149046 - CVE-2014-3684 torque: non-root users able to kill any process on any node in a job [epel-5]
        https://bugzilla.redhat.com/show_bug.cgi?id=1149046
  [ 4 ] Bug #1149047 - CVE-2014-3684 torque: non-root users able to kill any process on any node in a job [epel-6]
        https://bugzilla.redhat.com/show_bug.cgi?id=1149047
  [ 5 ] Bug #1029754 - CVE-2013-4495 torque: arbitrary code execution via job submission [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1029754
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update torque' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the epel-package-announce mailing list