Vulnerability Name: | CVE-2014-0476 (CCN-93603) | ||||||||||||||||||||
Assigned: | 2013-12-19 | ||||||||||||||||||||
Published: | 2014-06-04 | ||||||||||||||||||||
Updated: | 2017-09-19 | ||||||||||||||||||||
Summary: | The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. Note: this is only a vulnerability when /tmp is not mounted with the noexec option. | ||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P) 3.1 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-0476 Source: OSVDB Type: UNKNOWN 107710 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/134484/Chkrootkit-Local-Privilege-Escalation.html Source: CCN Type: Full Disclosure Mailing List: Wed 4 Jun 2014 More /tmp fun (PHP, Lynis) Source: CCN Type: chkrootkit Web site chkrootkit Source: CONFIRM Type: Vendor Advisory http://www.chkrootkit.org/ Source: DEBIAN Type: UNKNOWN DSA-2945 Source: CCN Type: oss-security Mailing List, Wed 04 Jun 2014 CVE-2014-0476 chkrootkit vulnerability Source: MLIST Type: Exploit [oss-security] 20140604 CVE-2014-0476 chkrootkit vulnerability Source: CCN Type: BID-67813 chkrootkit 'slapper()' Function Local Privilege Escalation Vulnerability Source: UBUNTU Type: UNKNOWN USN-2230-1 Source: XF Type: UNKNOWN chkrootkit-cve20140476-priv-esc(93603) Source: CCN Type: Packet Storm Security [11-20-2015] Chkrootkit Local Privilege Escalation Source: GENTOO Type: UNKNOWN GLSA-201709-05 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [06-28-2014] Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [11-20-2015] Source: EXPLOIT-DB Type: UNKNOWN 38775 Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-0476 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |