GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Mar 14, 2019 4:26 am Post subject: [ GLSA 201903-11 ] XRootD |
|
|
Gentoo Linux Security Advisory
Title: XRootD: Remote code execution (GLSA 201903-11)
Severity: normal
Exploitable: remote
Date: 2019-03-14
Bug(s): #638420
ID: 201903-11
Synopsis
A vulnerability was discovered in XRootD which could lead to the
remote execution of code.
Background
A project that aims at giving high performance, scalable, and fault
tolerant access to data repositories of many kinds.
Affected Packages
Package: net-libs/xrootd
Vulnerable: < 4.8.3
Unaffected: >= 4.8.3
Architectures: All supported architectures
Description
A shell command injection was discovered in XRootD.
Impact
A remote attacker could execute arbitrary code.
Workaround
There is no known workaround at this time.
Resolution
All XRootD users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/xrootd-4.8.3"
|
References
CVE-2017-1000215
|
|