{"id":"UBUNTU-CVE-2011-2907","details":"Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.","modified":"2026-04-22T09:07:14.199322Z","published":"2011-08-15T19:55:00Z","upstream":["CVE-2011-2907"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-2907"},{"type":"REPORT","url":"https://wiki.egi.eu/wiki/SVG:Advisory-SVG-2011-2296"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-2907"}],"affected":[{"package":{"name":"torque","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/torque@2.4.16+dfsg-1.3ubuntu1.1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.16+dfsg-1ubuntu1","2.4.16+dfsg-1ubuntu2","2.4.16+dfsg-1.3ubuntu1","2.4.16+dfsg-1.3ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libtorque2","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-client","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-client-x11","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-common","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-mom","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-pam","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-scheduler","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"},{"binary_name":"torque-server","binary_version":"2.4.16+dfsg-1.3ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-2907.json"}},{"package":{"name":"torque","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/torque@2.4.16+dfsg-1.5?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.16+dfsg-1.5"],"ecosystem_specific":{"binaries":[{"binary_name":"libtorque2","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-client","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-client-x11","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-common","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-mom","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-pam","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-scheduler","binary_version":"2.4.16+dfsg-1.5"},{"binary_name":"torque-server","binary_version":"2.4.16+dfsg-1.5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-2907.json"}}],"schema_version":"1.7.5","severity":[{"type":"Ubuntu","score":"medium"}]}