CVE-2014-0476
Publication date 4 June 2014
Last updated 24 July 2024
Ubuntu priority
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
Status
Package | Ubuntu Release | Status |
---|---|---|
chkrootkit | 14.04 LTS trusty |
Fixed 0.49-4.1ubuntu1.14.04.1
|
References
Related Ubuntu Security Notices (USN)
- USN-2230-1
- chkrootkit vulnerability
- 4 June 2014