Untrusted search path in Slurm - CVE-2010-3380
Published: September 29, 2010 / Updated: January 29, 2021
Slurm
SchedMD
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the init.d/slurm and init.d/slurmdbd scripts place the . (dot) directory in the LD_LIBRARY_PATH. A local user can place a malicious binary into the current working directory and escalate privileges on the system.