This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Globus First view 2006-08-18
Product Globus Toolkit Last view 2012-06-07
Version 3.2.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:globus:globus_toolkit

Activity : Overall

Related : CVE

  Date Alert Description
7.6 2012-06-07 CVE-2012-3292

The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.

7.8 2007-05-21 CVE-2007-2784

Unspecified vulnerability in globus-job-manager in Globus Toolkit 4.1.1 and earlier (globus_nexus-6.6 and earlier) allows remote attackers to cause a denial of service (resource exhaustion and system crash) via certain requests to temporary TCP ports for a GRAM2 job or its MPICH-G2 applications.

3.6 2006-08-18 CVE-2006-4233

Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1) myproxy-admin-adduser, (2) grid-ca-sign, and (3) grid-security-config.

1.2 2006-08-18 CVE-2006-4232

Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-264 Permissions, Privileges, and Access Controls

Open Source Vulnerability Database (OSVDB)

id Description
36094 Globus Toolkit globus-job-manager MPICH-G2 Application GRAM2 Job Unspecified DoS
28020 Globus Toolkit grid-proxy-init File I/O Race Condition Credential Disclosure
28019 Globus Toolkit grid-security-config Symlink Arbitrary File Disclosure
28018 Globus Toolkit grid-ca-sign Symlink Arbitrary File Disclosure
28017 Globus Toolkit myproxy-admin-adduser Symlink Arbitrary File Disclosure

OpenVAS Exploits

id Description
2012-08-30 Name : Fedora Update for globus-gridftp-server-control FEDORA-2012-8445
File : nvt/gb_fedora_2012_8445_globus-gridftp-server-control_fc17.nasl
2012-08-30 Name : Fedora Update for globus-gridftp-server FEDORA-2012-8445
File : nvt/gb_fedora_2012_8445_globus-gridftp-server_fc17.nasl
2012-08-10 Name : Debian Security Advisory DSA 2523-1 (globus-gridftp-server)
File : nvt/deb_2523_1.nasl
2012-06-04 Name : Fedora Update for globus-gridftp-server-control FEDORA-2012-8461
File : nvt/gb_fedora_2012_8461_globus-gridftp-server-control_fc16.nasl
2012-06-04 Name : Fedora Update for globus-gridftp-server FEDORA-2012-8461
File : nvt/gb_fedora_2012_8461_globus-gridftp-server_fc16.nasl
2012-06-04 Name : Fedora Update for globus-gridftp-server-control FEDORA-2012-8488
File : nvt/gb_fedora_2012_8488_globus-gridftp-server-control_fc15.nasl
2012-06-04 Name : Fedora Update for globus-gridftp-server FEDORA-2012-8488
File : nvt/gb_fedora_2012_8488_globus-gridftp-server_fc15.nasl
2008-09-04 Name : FreeBSD Ports: globus
File : nvt/freebsd_globus.nasl

Nessus® Vulnerability Scanner

id Description
2012-08-07 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-2523.nasl - Type: ACT_GATHER_INFO
2012-06-27 Name: The remote FTP service is vulnerable to an authentication bypass attack.
File: gt_gridftp_6_11.nasl - Type: ACT_GATHER_INFO
2012-06-04 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2012-8445.nasl - Type: ACT_GATHER_INFO
2012-06-04 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2012-8461.nasl - Type: ACT_GATHER_INFO
2012-06-04 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2012-8488.nasl - Type: ACT_GATHER_INFO
2006-08-21 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_5039ae612c9f11db8401000ae42e9b93.nasl - Type: ACT_GATHER_INFO