CVE-2014-0748

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/12/2014
Last modified:
12/04/2025

Description

apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cray:cray_linux_environment:*:*:*:*:*:*:*:* 4.2 (including)
cpe:2.3:o:cray:cray_linux_environment:5.1:*:*:*:*:*:*:*