CVE-2014-0476
chkrootkit <0.50 - Code Injection
Title source: llmDescription
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/38775
exploitdb
WRITEUP
VERIFIED
by Thomas Stangner · textlocallinux
https://www.exploit-db.com/exploits/33899
metasploit
WORKING POC
MANUAL
by Thomas Stangner, Julien, Voisin · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/local/chkrootkit.rb
References (8)
Scores
EPSS
0.1144
EPSS Percentile
93.6%
Details
CWE
CWE-20
Status
published
Products (5)
canonical/ubuntu_linux
10.04
canonical/ubuntu_linux
12.04
canonical/ubuntu_linux
13.10
canonical/ubuntu_linux
14.04
chkrootkit/chkrootkit
< 0.49
Published
Oct 25, 2014
Tracked Since
Feb 18, 2026