CVE-2014-0476
LOW 3.7EPSS 3.8%
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
- CVSS v2.0
- 3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P - EPSS
- 3.83% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2014-10-25
- Updated
- 2024-08-06