CVE-2014-0476
25.10.2014, 22:55
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.Enginsight
Vendor | Product | Version |
---|---|---|
chkrootkit | chkrootkit | 𝑥 ≤ 0.49 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 13.10 |
canonical | ubuntu_linux | 14.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References