3.7
CVE-2014-0476
- EPSS 3.83%
- Veröffentlicht 25.10.2014 22:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chkrootkit ≫ Chkrootkit Version <= 0.49
Canonical ≫ Ubuntu Linux Version 10.04 Edition lts
Canonical ≫ Ubuntu Linux Version 12.04 Edition lts
Canonical ≫ Ubuntu Linux Version 13.10
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.83% | 0.887 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.7 | 1.9 | 6.4 |
AV:L/AC:H/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://osvdb.org/show/osvdb/107710
http://packetstormsecurity.com/files/134484/Chkrootkit-Local-Privilege-Escalation.html
http://www.chkrootkit.org/
http://www.debian.org/security/2014/dsa-2945
http://www.openwall.com/lists/oss-security/2014/06/04/9
http://www.ubuntu.com/usn/USN-2230-1
https://security.gentoo.org/glsa/201709-05
https://www.exploit-db.com/exploits/38775/