CVE-2014-0476

low
Published 2014-10-25 · Modified 2026-05-06
CVSS v3
CVSS v2
3.7
VIR risk
3.7

Description

The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0476

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.chkrootkit.org/

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.49-5
debian debianbullseyefixed0.49-5
debian debianforkyfixed0.49-5
debian debiansidfixed0.49-5
debian debiantrixiefixed0.49-5
ubuntu ubuntu10.04affected
ubuntu ubuntu12.04affected
ubuntu ubuntu13.10affected
ubuntu ubuntu14.04affected

Application impact

VendorProductVersionsFixed
chkrootkitchkrootkit{"endIncluding":"0.49"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.