[gt-user] Grid mapfile double-quote injection vulnerability

2014-10-16 Thread Paul Hopkins
Hi all, We currently use Globus tools within our organisation to allow our users to access a number of compute clusters. To manage the grid mapfiles across all of the cluster sites we have developed software that periodically downloads information from a central LDAP and updates the mapfile at eac

[gt-user] SSLv3 POODLE vulnerability CVE-2014-3566

2014-10-16 Thread Stuart Martin
Hi All, The Globus dev team has reviewed all Globus services and Globus Toolkit components to determine the impact of the SSLv3 “POODLE” vulnerability described in CVE-2014-3566. We have created a page where details about this issue will be communicated. https://support.globus.org/entries/10

Re: [gt-user] Grid mapfile double-quote injection vulnerability

2014-10-16 Thread Joseph Bester
These are intended to be used by sysadmins, and it's pretty explicit about what it does, so it should hopefully be clear when weird things are being added to the gridmap. That said, it would be good to have some better error checking: - Escape quotes in the DN passed on the command-line - Check