Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Julien Voisin

#52598de 53,638
3.7CVSS total
Vulnerabilidades · 1
PT-2014-3646
3.7
2014-06-04
Noble M. Kellogg · Chkrootkit · CVE-2014-0476
**Name of the Vulnerable Software and Affected Versions** chkrootkit versions prior to 0.50 **Description** The issue arises from the slapper function in chkrootkit, which fails to properly quote file paths. This allows local users to execute arbitrary code via a Trojan horse executable, but only when /tmp is not mounted with the noexec option. **Recommendations** For versions prior to 0.50, update to version 0.50 or later to resolve the issue. As a temporary workaround, consider mounting /tmp with the noexec option to minimize the risk of exploitation.