{"id":"MGASA-2013-0327","summary":"Updated torque packages fix CVE-2013-4495","details":"Updated torque packages fix security vulnerability:\n\nA user could submit executable shell commands on the tail of what is passed\nwith the -M switch for qsub. This was later passed to a pipe, making it\npossible for these commands to be executed as root on the pbs_server\n(CVE-2013-4495).\n","modified":"2026-04-16T06:23:43.245357603Z","published":"2013-11-18T14:41:45Z","upstream":["CVE-2013-4495"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0327.html"},{"type":"WEB","url":"http://www.supercluster.org/pipermail/torqueusers/2013-November/016425.html"},{"type":"WEB","url":"http://www.debian.org/security/2013/dsa-2796"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11670"}],"affected":[{"package":{"name":"torque","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/torque?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.12-1.2.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0327.json"}},{"package":{"name":"torque","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/torque?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.5.1-1.2.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0327.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}