On Oct 21, 2006, at 2:40 PM, Lorne Levinson wrote:
> I saw that a new version of Torque 2, 2.1.4, was put last night on:
> http://www.clusterresources.com/downloads/torque/
> The changelog reads:
>
> 2.1.4
> b - fix cput job status
> b - Fix "Spool Job Race condition"
Hi Lorne,
The 2.1.4 released by SuperCluster does indeed fix the security hole/
There is now also 2.1.5 release which fixed a bug introduced by the
security fix. Note the bug is not relevant to the fix that was
broadcasted
on Friday.
>
> Has anyone confirmed that this closes the reported security hole?
>
> The LCG/EGEE Torque version is 1.0.1. Is there a known reason why it
> is not Torque 2? Is there a reason not to upgrade to Torque 2?
>
Indeed.
https://savannah.cern.ch/patch/?func=detailitem&item_id=832
is work in progress to achieve this. This item will now be updated to
2.1.5 of course.
Steve
> Lorne
--
Steve Traylen
[log in to unmask]
CERN, IT-GD-OPS.
|