vendor:
Chkrootkit
by:
Thomas Stangner, Julien 'jvoisin' Voisin
7,2
CVSS
HIGH
Privilege Escalation
20
CWE
Product Name: Chkrootkit
Affected Version From: 0.1
Affected Version To: 0.4
Patch Exists: YES
Related CWE: CVE-2014-0476
CPE: a:chkrootkit:chkrootkit
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2014
Chkrootkit Local Privilege Escalation
Chkrootkit before 0.50 will run any executable file named /tmp/update as root, allowing a trivial privsec. WfsDelay is set to 24h, since this is how often a chkrootkit scan is scheduled by default.
Mitigation:
Upgrade to the latest version of Chkrootkit