CVE-2014-0476

chkrootkit <0.50 - Code Injection

Title source: llm

Description

The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/38775
exploitdb WRITEUP VERIFIED
by Thomas Stangner · textlocallinux
https://www.exploit-db.com/exploits/33899
metasploit WORKING POC MANUAL
by Thomas Stangner, Julien, Voisin · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/local/chkrootkit.rb

Scores

EPSS 0.1144
EPSS Percentile 93.6%

Details

CWE
CWE-20
Status published
Products (5)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 13.10
canonical/ubuntu_linux 14.04
chkrootkit/chkrootkit < 0.49
Published Oct 25, 2014
Tracked Since Feb 18, 2026