Vulnerability Bulletins

DSA-4023 slurm-llnl - security update

   
Affected software Debian
 
Ryan Day discovered that the Simple Linux Utility for ResourceManagement (SLURM), a cluster resource management and job schedulingsystem, does not properly handle SPANK environment variables, allowing auser permitted to submit jobs to execute code as root during the Prologor Epilog. All systems using a Prolog or Epilog script are vulnerable,regardless of whether SPANK plugins are in use.

More info:

https://www.debian.org/security/2017/dsa-4023