CVE-2017-1000203
high
CVSS v3
8.8
CVSS v2
9.0
VIR risk
8.8
Description
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/root-project/root/commit/88ccff152604e0f1012653a596d802ff7ede3145#diff-6cd6f6c31bac70116b7ca7abdc8e517e
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cern | root | {"endIncluding":"6.9.03"} | |
References
CWEs
CWE-78
Verify integrity in audit chain (admin only). AS-IS.