CVE-2018-20871

NameCVE-2018-20871
DescriptionIn Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gridengine (PTS)buster8.1.9+dfsg-9fixed
bullseye8.1.9+dfsg-9.1fixed
bookworm8.1.9+dfsg-10fixed
sid, trixie8.1.9+dfsg-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gridenginesource(unstable)(not affected)

Notes

- gridengine <not-affected> (Vulnerable code specific to Univa Grid Engine fork)

Search for package or bug name: Reporting problems