3.7

CVE-2014-0476

Exploit
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable.  NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ChkrootkitChkrootkit Version <= 0.49
CanonicalUbuntu Linux Version10.04 Editionlts
CanonicalUbuntu Linux Version12.04 Editionlts
CanonicalUbuntu Linux Version13.10
CanonicalUbuntu Linux Version14.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.44% 0.933
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.7 1.9 6.4
AV:L/AC:H/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.