CVE-2006-5677 describes a local privilege escalation vulnerability in TORQUE Resource Manager versions 2.0.0p8 and earlier. An attacker can exploit a symlink race condition in resmom/start_exec.c to create arbitrary files, specifically targeting job output files in /usr/spool/PBS/spool and potentially job files in /usr/spool/PBS/mom_priv/jobs. This vulnerability has a CVSS score of 7.2, indicating high severity with local access, low attack complexity, and complete impact on confidentiality, integrity, and availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received no community discussion or media coverage, further indicating a low profile and limited attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0p8CPE matchmatch criteria | cpe:2.3:a:cluster_resources:torque_resource_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.