2017-11-16 14:14:55 -07:00
|
|
|
{
|
2019-03-18 04:44:51 +00:00
|
|
|
"CVE_data_meta": {
|
|
|
|
"ASSIGNER": "cve@mitre.org",
|
|
|
|
"DATE_ASSIGNED": "2017-08-22T17:29:33.444131",
|
|
|
|
"ID": "CVE-2017-1000215",
|
|
|
|
"REQUESTER": "fabian.freyer@physik.tu-berlin.de",
|
|
|
|
"STATE": "PUBLIC"
|
|
|
|
},
|
|
|
|
"affects": {
|
|
|
|
"vendor": {
|
|
|
|
"vendor_data": [
|
|
|
|
{
|
|
|
|
"product": {
|
|
|
|
"product_data": [
|
|
|
|
{
|
|
|
|
"product_name": "n/a",
|
|
|
|
"version": {
|
|
|
|
"version_data": [
|
|
|
|
{
|
|
|
|
"version_value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"vendor_name": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
},
|
|
|
|
"data_format": "MITRE",
|
|
|
|
"data_type": "CVE",
|
|
|
|
"data_version": "4.0",
|
|
|
|
"description": {
|
|
|
|
"description_data": [
|
2017-11-17 10:39:20 -07:00
|
|
|
{
|
2019-03-18 04:44:51 +00:00
|
|
|
"lang": "eng",
|
|
|
|
"value": "ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution"
|
2017-11-16 14:14:55 -07:00
|
|
|
}
|
2019-03-18 04:44:51 +00:00
|
|
|
]
|
|
|
|
},
|
|
|
|
"problemtype": {
|
|
|
|
"problemtype_data": [
|
|
|
|
{
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
|
|
|
"value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"references": {
|
|
|
|
"reference_data": [
|
|
|
|
{
|
|
|
|
"name": "https://github.com/xrootd/xrootd/blob/befa2e627a5a33a38c92db3e57c07d8246a24acf/src/XrdSecgsi/XrdSecgsiGMAPFunLDAP.cc#L85",
|
|
|
|
"refsource": "MISC",
|
|
|
|
"url": "https://github.com/xrootd/xrootd/blob/befa2e627a5a33a38c92db3e57c07d8246a24acf/src/XrdSecgsi/XrdSecgsiGMAPFunLDAP.cc#L85"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "GLSA-201903-11",
|
|
|
|
"refsource": "GENTOO",
|
|
|
|
"url": "https://security.gentoo.org/glsa/201903-11"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "https://github.com/xrootd/xrootd/blob/v4.6.1/docs/ReleaseNotes.txt",
|
|
|
|
"refsource": "CONFIRM",
|
|
|
|
"url": "https://github.com/xrootd/xrootd/blob/v4.6.1/docs/ReleaseNotes.txt"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf",
|
|
|
|
"refsource": "CONFIRM",
|
|
|
|
"url": "https://github.com/xrootd/xrootd/commit/befa2e627a5a33a38c92db3e57c07d8246a24acf"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|