ISOMAN

CVE

CVE-2014-0476

The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

Severity
LOW
CVSS
3.7
Published
Modified

Linked Releases

References

  1. http://osvdb.org/show/osvdb/107710
  2. http://packetstormsecurity.com/files/134484/Chkrootkit-Local-Privilege-Escalation.html
  3. http://www.chkrootkit.org/
  4. http://www.debian.org/security/2014/dsa-2945
  5. http://www.openwall.com/lists/oss-security/2014/06/04/9
  6. http://www.ubuntu.com/usn/USN-2230-1
  7. https://security.gentoo.org/glsa/201709-05
  8. https://www.exploit-db.com/exploits/38775/
  9. http://osvdb.org/show/osvdb/107710
  10. http://packetstormsecurity.com/files/134484/Chkrootkit-Local-Privilege-Escalation.html
  11. http://www.chkrootkit.org/
  12. http://www.debian.org/security/2014/dsa-2945
  13. http://www.openwall.com/lists/oss-security/2014/06/04/9
  14. http://www.ubuntu.com/usn/USN-2230-1
  15. https://security.gentoo.org/glsa/201709-05
  16. https://www.exploit-db.com/exploits/38775/