Jump to content
  • Announcements

    • admin

      PBS Forum Has Closed   06/12/17

      The PBS Works Support Forum is no longer active.  For PBS community-oriented questions and support, please join the discussion at http://community.pbspro.org.  Any new security advisories related to commercially-licensed products will be posted in the PBS User Area (https://secure.altair.com/UserArea/). 
smgoosen

SECURITY BULLETIN PBS13-01

Recommended Posts

DESCRIPTION:


 


Altair Engineering is releasing this advisory to customers running PBS Professional to alert them to a security vulnerability. This is a privilege escalation vulnerability that potentially affects all customers.  An attacker who successfully exploits this vulnerability could gain administrator privilege (root access) on PBS server (aka headnode) hosts. The attacker would need to be an authenticated user authorized to submit jobs on the cluster.


 


SEVERITY RATING:


Critical


 


RECOMMENDATION:


Altair recommends that all customers running their PBS Professional server on a Linux and/or Unix based OS apply this update in a timely fashion. 


 


AFFECTED SOFTWARE:


All currently released Linux and Unix versions of PBS Professional


 


SCHEDULE OF AVAILABILITY OF UPDATE:


 


PBS Professional patch is applicable to all affected releases 10.x and newer (attached to this bulletin)


PBS Professional 12.2.0 (available Dec 2013)


NOTE: Altair advises customers running any 10.x or prior release upgrade to at least v10.4.7.


 


SECURITY UPDATE:


The updates and packages are being made available to all customers running PBS Professional software. For customers with current maintenance and support contracts, the updates are available from the user login area of the PBS Professional website. For customers who do not have access to this area, please see below for instructions on getting the required update. Please refer to the release notes and installation instructions included in each package.


 


INSTRUCTIONS TO OBTAIN UPDATE:


For customers with active support, please go to:


http://www.pbspro.com/UserArea/


log in with your site ID and password to obtain the desired packages.


 


For customers without active support, please send an email to:


pbssupport@altair.com


Please include the version of PBS Professional you are running,


the operating system you are using, and the hardware/platform you are running on. 


This will help us expedite your request.


 


Please contact pbssupport@altair.com if you need additional information.


 


Altair would like to thank Cray Inc for reporting this issue.


 


 


13-01_verify_mail.tar.gz

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now

×