CVE-2018-10995

EUVD-2018-3046
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
schedmdslurm
𝑥
≤ 17.02.10.1
schedmdslurm
17.11.0.0:pre1
schedmdslurm
17.11.0.0:pre2
schedmdslurm
17.11.0.0:rc1
schedmdslurm
17.11.0.0:rc2
schedmdslurm
17.11.0.0:rc3
schedmdslurm
17.11.0.1
schedmdslurm
17.11.1.1
schedmdslurm
17.11.1.2
schedmdslurm
17.11.2.1
schedmdslurm
17.11.3.1
schedmdslurm
17.11.3.2
schedmdslurm
17.11.4.1
schedmdslurm
17.11.5.1
schedmdslurm
17.11.6.1
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
slurm-llnl
bionic
Fixed 17.11.2-1ubuntu0.1~esm3
released
eoan
dne
focal
not-affected
groovy
not-affected
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
trusty
Fixed 2.6.5-1ubuntu0.1~esm4
released
xenial
Fixed 15.08.7-1ubuntu0.1~esm5
released