CVE-2014-0476

Publication date

2014-10-25 22:00:00

Family

debian

State

PUBLISHED

Description

The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.